HomeDefault status
affected
Any version
affected
Default status
affected
Any version
affected
Description
The Mstoreapp Mobile App WordPress plugin through 2.08 and Mstoreapp Mobile Multivendor through 9.0.1 do not properly verify users identify when using an AJAX action, allowing unauthenticated users to retrieve a valid session for arbitrary users by knowing their email address.
Problem types
CWE-639 Authorization Bypass Through User-Controlled Key
Product status
Any version
Any version
Credits
Khaled Alenazi (Nxploited)
WPScan
References
wpscan.com/...rability/6432bd1a-6e44-4a3f-890b-df2bd877d626/