What is CVE-2026-16038?
A vulnerability in the MStore API WordPress plugin (versions before 4.21.0) allows an unauthenticated attacker to mark an arbitrary order as fully paid. The plugin fails to verify payment with the payment gateway on several payment-completion endpoints, enabling the attacker to obtain goods or services without paying. Updating the plugin to the latest version is recommended.
Azərbaycanca: MStore API WordPress plaginində (4.21.0-dan əvvəlki versiyalar) autentifikasiya tələb etməyən zəiflik aşkar edilib. Təcavüzkar ödəniş tamamlanma endpointləri vasitəsilə ödənişi yoxlatmadan istənilən sifarişi ödənilmiş kimi qeyd edə bilər ki, bu da ödənişsiz mal və ya xidmət əldə etməyə imkan yaradır. Plaginin son versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which versions of the MStore API plugin are affected by CVE-2026-16038?
The vulnerability affects MStore API plugin versions before 4.21.0.
What can an attacker achieve by exploiting this unauthenticated vulnerability?
An attacker can mark an arbitrary order as fully paid without payment verification, enabling them to obtain goods or services without paying.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.