Authentication Bypass in FluxBuilder's MStore API Software by FluxBuilder
CVE-2026-54817

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 June 2026

What is CVE-2026-54817?

An authentication bypass vulnerability in FluxBuilder's MStore API allows unauthorized users to exploit password recovery features. This weakness permits attackers to bypass authentication mechanisms and gain access to sensitive functions. The issue impacts MStore API versions from n/a to 4.18.4, necessitating immediate attention from users to mitigate potential exploitation.

Affected Version(s)

MStore API <= 4.18.4

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jakub Herman | Patchstack Bug Bounty Program
.