CVE-2026-16038
MStore API < 4.21.0 - Unauthenticated Payment Bypass via Multiple Payment Gateways
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order fully paid without paying and obtain goods or services for free.
| Vendor | unknown |
| Product | mstore api |
| Published | Aug 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown mstore api
Be the first to know when new unknown vulnerabilities affecting unknown mstore api are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / MStore API
0 < 4.21.0
References
Credits
Sai Praneeth Koti WPScan