S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-2732 Scanner

Detects 'Authentication Bypass' vulnerability in inspireui MStore API plugin for WordPress affects v. through 3.9.2.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-2732
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insufficient verification on the user being supplied during the add listing REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
MStore API – Create Native Android & iOS Apps On The Cloudby inspireui
0
Updated Aug 19, 2026View on NVD →
Detail

The Inspireui MStore API plugin for WordPress is a powerful tool used for connecting mobile apps with WooCommerce stores. This plugin is designed to make the process of building and managing online stores easier, faster and more efficient. The MStore API plugin enables developers and business owners to connect their WooCommerce store with a mobile app that can be accessed by their customers on different devices.

However, recently this popular plugin has been found to have a serious vulnerability flaw with the CVE-2023-2732 code. The vulnerability has been discovered in the authentication system of the plugin which can be easily bypassed, and it allows attackers to log in as any existing user on the site if they have access to their user id. The vulnerability is present in plugin versions up to and including 3.9.2.

This vulnerability can cause serious damage to a website if exploited by attackers. Hackers can gain access to sensitive information stored on the website such as usernames and passwords. The attackers can also execute malicious code and compromise the security of the website with little to no resistance.

Thanks to the pro features of the s4e.io platform, website owners can easily and quickly learn about vulnerabilities in their digital assets. The platform provides comprehensive information about cyber threats in real-time, empowering businesses and website owners to take action proactively and prevent potential damage. By leveraging the free vulnerability scanner feature, website owners can use the platform to scan and identify weaknesses in their website's security. 

 

REFERENCES

Solution Advice

To protect against this vulnerability, there are some precautions that can be taken. Here are a few bullet points:

  • Immediately update the plugin to the latest version. The latest version of the plugin is no longer susceptible to this vulnerability and has been patched.
  • Use a robust and secure password for your user account in WordPress to prevent unauthorized access.
  • Monitor login activity on your WordPress site by using two-factor authentication.
  • Disable add user, edit user, and delete user features in the WordPress dashboard if they are not required to prevent attackers from creating new accounts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.