HIGH 7.5 NVD

CVE-2026-16041

The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing a

The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chosen reviewer name, email and star rating on stores configured to accept reviews only from verified owners.

References

Published: 2026-08-07 · Source: NVD · Feed updated: 2026-08-10
This high severity vulnerability with a CVSS score of 7.5 was published on 2026-08-07 via NVD.
vulnfeed aggregates 8893 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.