Arbitrary File Upload Vulnerability in MStore API Plugin
CVE-2024-8242
8.8HIGH
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 13 September 2024
What is CVE-2024-8242?
The MStore API plugin for WordPress has a vulnerability that permits authenticated users, including those with subscriber-level access, to upload arbitrary files due to insufficient file type validation in the update_user_profile() function. This issue affects all versions up to and including 4.15.3. By exploiting this vulnerability, attackers can place potentially malicious files on the server, which may be used for remote code execution. Additionally, when combined with a registration endpoint open to unauthenticated users, this vulnerability can be leveraged to create more severe security risks.
Affected Version(s)
MStore API – Create Native Android & iOS Apps On The Cloud * <= 4.15.3