← Back to CVE search

CVE-2021-47933

MStore API

Description

WordPress MStore API 2.0.6 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the REST API endpoint. Attackers can upload PHP files with arbitrary names to the config_file endpoint to achieve remote code execution on the server.

CVSS 9.8EPSS 0.587%Risk 1.03
View source
Published
2026-05-10 13:16:29
Affected versions
cannotmatch
Type
Installed app
Last modified
2026-07-25 10:10:00
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H