/Vulnerability Library

WordPress MStore API <= 4.0.1 - Unauthenticated SQL Injection

CVE-2023-3197
Verified

Description

MStore API plugin for WordPress up to version 4.0.1 contains an unauthenticated blind SQL injection caused by insufficient escaping of 'id' parameter in SQL queries, letting attackers execute arbitrary SQL commands without authentication, exploit requires sending crafted requests with malicious 'id' parameter.

Severity

Critical

Published Date

February 6, 2026

Template Author

shivam kamboj

CVE-2023-3197.yaml
9.5Severity

CVSS Metrics

References

https://nvd.nist.gov/vuln/detail/CVE-2023-3197https://www.wordfence.com/threat-intel/vulnerabilities/id/30aab1af-a78f-4bac-b3c5-30ea854ccef7?source=cve

Remediation Steps

Update to the latest version of the plugin where the vulnerability is fixed.