WordPress MStore API <= 4.0.1 - Unauthenticated SQL Injection
CVE-2023-3197
Verified
Description
MStore API plugin for WordPress up to version 4.0.1 contains an unauthenticated blind SQL injection caused by insufficient escaping of 'id' parameter in SQL queries, letting attackers execute arbitrary SQL commands without authentication, exploit requires sending crafted requests with malicious 'id' parameter.
Severity
Critical
Published Date
February 6, 2026
Template Author
shivam kamboj
CVE-2023-3197.yaml
Remediation Steps
Update to the latest version of the plugin where the vulnerability is fixed.