CVE-2026-16039 PUBLISHED

MStore API < 4.21.0 - Subscriber+ Order and Customer PII Disclosure via IDOR

Assigner: WPScan
Reserved: 17.07.2026 Published: 07.08.2026 Updated: 07.08.2026

The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders, allowing any authenticated user, including Subscribers, to read every WooCommerce order in the store together with each customer's personal information.

Product Status

Vendor Unknown
Product MStore API
Versions Default: unaffected
  • affected from 0 to 4.21.0 (excl.)

Credits

  • Sai Praneeth Koti finder
  • WPScan coordinator

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE