Vulnerability Description
A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign In With Apple allowing unauthenticated users to recover an authentication cookie with only an email address.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Inspireui | Mstore Api | < 3.2.0 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/bf5ddc43-974d-41fa-8276-c1a27d3cc882Third Party Advisory
- https://wpscan.com/vulnerability/bf5ddc43-974d-41fa-8276-c1a27d3cc882Third Party Advisory
FAQ
What is CVE-2021-24148?
CVE-2021-24148 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign In With Apple allowing unauthenticated users to recover an authentication cooki...
How severe is CVE-2021-24148?
CVE-2021-24148 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-24148?
Check the references section above for vendor advisories and patch information. Affected products include: Inspireui Mstore Api.