CVE-2026-16039
MStore API < 4.21.0 - Subscriber+ Order and Customer PII Disclosure via IDOR
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders, allowing any authenticated user, including Subscribers, to read every WooCommerce order in the store together with each customer's personal information.
| Vendor | unknown |
| Product | mstore api |
| Published | Aug 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown mstore api
Be the first to know when new unknown vulnerabilities affecting unknown mstore api are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / MStore API
0 < 4.21.0
References
Credits
Sai Praneeth Koti WPScan