What is CVE-2026-16041?
The MStore API WordPress plugin before version 4.21.0 lacks authorization and purchase-ownership checks on its REST product-review creation route. This vulnerability allows an unauthenticated attacker to create fake WooCommerce product reviews with an arbitrary reviewer name, email, and star rating. Updating to the latest plugin version is strongly advised.
Azərbaycanca: MStore API WordPress plagininin 4.21.0-dən əvvəlki versiyalarında REST API üzərindən məhsul rəyi yaratmaq üçün avtorizasiya və alış yoxlaması aparılmır. Bu boşluq autentifikasiya olunmamış hücumçuya WooCommerce mağazalarında istədiyi ad, email və ulduz reytinqi ilə saxta rəylər yerləşdirməyə imkan verir. Plaginin ən son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the MStore API plugin are affected by CVE-2026-16041?
This vulnerability affects MStore API WordPress plugin versions prior to 4.21.0.
What can an unauthenticated attacker do by exploiting this vulnerability?
An unauthenticated attacker can create fake WooCommerce product reviews with arbitrary reviewer name, email, and star rating via the REST API route.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.