CVE-2026-16041
MStore API < 4.21.0 - Unauthenticated Product Review Creation
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chosen reviewer name, email and star rating on stores configured to accept reviews only from verified owners.
| Vendor | unknown |
| Product | mstore api |
| Published | Aug 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown mstore api
Be the first to know when new unknown vulnerabilities affecting unknown mstore api are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / MStore API
0 < 4.21.0
References
Credits
Usama Arshad WPScan