MStore API – Create Native Android & iOS Apps On The Cloud

MStore API – Create Native Android & iOS Apps On The Cloud has 38 disclosed vulnerabilities in the WordSec catalog, reported between 2020 and 2026; all 38 are fixed as of September 2026. Their average CVSS score is 7.0, and the most serious one scores 9.8 out of 10. Severity breakdown: 14 critical and 3 high. 2023 was the busiest year with 17 disclosures.

The most common weakness is Authentication Bypass Using An Alternate Path Or Channel, behind 8 of the records (21%). Other recurring categories include Cross-Site Request Forgery (CSRF), Missing Authorization.

Every one of the 38 issues recorded for MStore API – Create Native Android & iOS Apps On The Cloud has a vendor fix available, so running the current release closes all known holes.

20 independent researchers contributed these findings, most of them (14) reported by Truoc Phan. MStore API – Create Native Android & iOS Apps On The Cloud is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

01234567891023.09.2019Today11.03.20209.8MStore API <= 2.1.5 - Authentication Bypass CVSS 9.8 · 11.03.202002.02.20219.8MStore API <= 3.1.9 - Authentication Bypass CVSS 9.8 · 02.02.202105.10.20219.8MStore API < 3.4.5 - Arbitrary File Upload CVSS 9.8 · 05.10.202117.05.20239.8MStore API <= 3.9.0 - Authentication Bypass CVSS 9.8 · 17.05.202322.05.20239.8MStore API <= 3.9.1 - Authentication Bypass CVSS 9.8 · 22.05.202324.05.20239.8MStore API <= 3.9.2 - Authentication Bypass CVSS 9.8 · 24.05.202312.06.20236.5MStore API <= 3.9.6 - Missing Authorization CVSS 6.5 · 12.06.202313.06.20234.3MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Title Update CVSS 4.3 · 13.06.20234.3MStore API <= 3.9.6 - Cross-Site Request Forgery to Product Limit Update CVSS 4.3 · 13.06.20234.3MStore API <= 3.9.6 - Cross-Site Request Forgery to Firebase Server Key Update CVSS 4.3 · 13.06.20234.3MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Title Update CVSS 4.3 · 13.06.20234.3MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Status Update CVSS 4.3 · 13.06.20234.3MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Message Update CVSS 4.3 · 13.06.202319.06.20239.8MStore API <= 3.9.7 - Unauthenticated SQL Injection CVSS 9.8 · 19.06.20239.8MStore API <= 3.9.8 - Unauthenticated Privilege Escalation CVSS 9.8 · 19.06.20239.8MStore API <= 4.10.7 - Unauthorized Account Access and Privilege Escalation CVSS 9.8 · 19.06.20239.8MStore API <= 3.9.7 - Unauthenticated SQL Injection CVSS 9.8 · 19.06.202323.06.20239.8MStore API <= 4.0.1 - Unauthenticated SQL Injection CVSS 9.8 · 23.06.202303.10.20238.8MStore API <= 4.0.6 - Authenticated (Subscriber+) SQL Injection CVSS 8.8 · 03.10.202326.12.20234.3MStore API <= 4.10.1 - Cross-Site Request Forgery CVSS 4.3 · 26.12.202311.07.20249.8MStore API – Create Native Android & iOS Apps On The Cloud <= 4.14.7 - Authentication Bypass CVSS 9.8 · 11.07.202414.08.20248.1MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.2 - Authentication Bypass to Account Takeover CVSS 8.1 · 14.08.202412.09.20247.3MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.3 - Unauthorized User Registration CVSS 7.3 · 12.09.20244.3MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.3 - Authenticated (Subscriber+) Limited Arbitrary File Upload CVSS 4.3 · 12.09.202419.11.20246.5MStore API <= 4.15.7 - Authenticated (Subscriber+) SQL Injection CVSS 6.5 · 19.11.202412.12.20245.4MStore API – Create Native Android & iOS Apps On The Cloud <= 4.16.4 - Authenticated (Subscriber+) HTML File Upload (Stored Cross-Site Scripting) CVSS 5.4 · 12.12.202401.05.20256.5MStore API – Create Native Android & iOS Apps On The Cloud <= 4.17.4 - Unauthenticated Limited Privilege Escalation CVSS 6.5 · 01.05.202526.05.20254.3MStore API – Create Native Android & iOS Apps On The Cloud <= 4.17.5 - Missing Authorization to Authenticated (Subscriber+) Posts Creation CVSS 4.3 · 26.05.202508.04.20264.3MStore API <= 4.18.3 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Meta Update CVSS 4.3 · 08.04.202617.06.20265.3MStore API – Create Native Android & iOS Apps On The Cloud <= 4.18.4 - Missing Authorization CVSS 5.3 · 17.06.202607.07.20265.3MStore API – Create Native Android & iOS Apps On The Cloud <= 4.18.4 - Missing Authorization CVSS 5.3 · 07.07.202603.08.20265.3MStore API <= 4.20.0 - Missing Authorization CVSS 5.3 · 03.08.20264.3MStore API <= 4.20.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) Order and Customer PII Disclosure CVSS 4.3 · 03.08.20265.3MStore API <= 4.20.0 - Missing Authorization CVSS 5.3 · 03.08.202611.08.20269.8MStore API – Create Native Android & iOS Apps On The Cloud <= 4.20.0 - Unauthenticated Privilege Escalation CVSS 9.8 · 11.08.202627.08.20266.3MStore API – Create Native Android & iOS Apps On The Cloud < 4.21.1 - Missing Authorization CVSS 6.3 · 27.08.20264.3MStore API – Create Native Android & iOS Apps On The Cloud < 4.21.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Order Completion CVSS 4.3 · 27.08.202604.09.20269.8MStore API <= 4.20.0 - Unauthenticated Authentication Bypass via 'id_token' Parameter JWT Forgery CVSS 9.8 · 04.09.2026

Strategic Overview

Avg CVSSMedium
7.0/ 10
Patch Coverage100%
Open

0

Fixed

38

Get automatic notifications for all MStore API – Create Native Android & iOS Apps On The Cloud vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2026-13447

MStore API <= 4.20.0 - Unauthenticated Authentication Bypass via 'id_token' Parameter JWT Forgery

Read the full analysis

Vulnerability Records

38 records
2026-09-04 17:19CVE-2026-13447
9.8
Critical
t4g0Yes
2026-08-27 00:00CVE-2026-18234
6.3
Medium
Erwan LRYes
2026-08-27 00:00CVE-2026-18233
4.3
Medium
Erwan LRYes
2026-08-11 00:00CVE-2026-27543
9.8
Critical
TaylsecYes
2026-08-03 00:00CVE-2026-16038
5.3
Medium
Sai Praneeth KotiYes
2026-08-03 00:00CVE-2026-16039
4.3
Medium
Sai Praneeth KotiYes
2026-08-03 00:00CVE-2026-16041
5.3
Medium
Usama ArshadYes
2026-07-07 00:00CVE-2026-57375
5.3
Medium
Nguyen Dinh Hai (HaiND)Yes
2026-06-17 00:00CVE-2026-54817
5.3
Medium
Jakub HermanYes
2026-04-08 00:00CVE-2026-3568
4.3
Medium
Osvaldo Noe Gonzalez Del Rio (Os)Yes
Showing 1–10 of 38 reports
MStore API – Create Native Android & iOS Apps On The Cloud banner
Latestv4.21.3

MStore API – Create Native Android & iOS Apps On The Cloud

FluxBuilder

Author

FluxBuilder

3.7(21)
74/100
Last Updated
2026-08-20 (24d ago)
Active Installs
2,000+
Downloads
307,999
Requires WP
4.4+
Requires PHP
0+
Tested up to
WP 7.1
Created
2019-09-23 (7y ago)

Take your WordPress store mobile with MStore API! This plugin bridges the gap between your WordPress website and the powerful FluxBuilder app builder. By enabling the REST API, MStore API seamlessly connects your store data (products, users, orders) to FluxBuilder App, allowing you to create a custom mobile app for your business without writing any code. Key benefits: Effortless mobile app creation: Leverage FluxBuilder’s drag-and-drop interface and pre-built templates to design your dream mobile app. Seamless data integration: MStore API ensures smooth communication between your WordPress store and the mobile app, keeping product information, user accounts, and orders in sync. Enhanced customer experience: Offer a convenient mobile shopping experience to your customers, boosting engagement and sales. Ready to go mobile? Download the MStore API plugin and unlock the power of FluxBuilder for your WordPress store! Reference links FluxBuilder – Flutter App Builder: https://www.fluxbuilder.com Guide to use: docs.fluxbuilder.com Download The App Builder: fluxbuilder.com/download Showcase: https://showcase.fluxbuilder.com YouTube Facebook Document

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C