PatchSiren cyber security CVE debrief
CVE-2026-16041 MStore API CVE debrief
The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chosen reviewer name, email and star rating on stores configured to accept reviews only from verified owners.
- Vendor
- MStore API
- Product
- MStore API WordPress plugin
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-07
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-07
- Advisory updated
- 2026-08-26
Who should care
Administrators of WordPress sites using the MStore API plugin should be aware of this vulnerability and take steps to patch it. Additionally, security teams monitoring for suspicious product review activity may want to investigate this vulnerability further. Site owners and security personnel responsible for maintaining WordPress installations should prioritize patching the plugin to prevent exploitation. Security teams may also want to review product review logs for potential malicious activity related to this vulnerability. IT managers overseeing WordPress deployments should ensure that the MStore API plugin is updated to version 4.21.0 or later to mitigate the risk of unauthorized product review creation. Compliance teams may also want to assess the potential impact of this vulnerability on their organization's risk profile and ensure that appropriate measures are taken to protect against exploitation. Furthermore, incident response teams should be prepared to investigate and respond to potential security incidents related to this vulnerability. Lastly, developers and DevOps teams should consider implementing additional security controls, such as monitoring and logging, to detect and prevent potential attacks. Security awareness training for personnel responsible for WordPress site management and security may also be beneficial in preventing similar vulnerabilities from being exploited in the future. Lastly, external security auditors may want to include this vulnerability in their risk assessments and penetration testing activities to ensure that organizations are adequately protected against exploitation. The MStore API plugin's vulnerability highlights the importance of robust security measures and proactive vulnerability management in WordPress deployments. By prioritizing patching and implementing additional security controls, organizations can reduce the risk of exploitation and protect their WordPress sites from potential attacks. Overall, a comprehensive approach to security and vulnerability management is essential in mitigating the risks associated with this vulnerability and ensuring the security of WordPress deployments. The vulnerability's impact
Technical summary
The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route. This allows an unauthenticated attacker to create WooCommerce product reviews with an attacker-chosen reviewer name, email, and star rating on stores configured to accept reviews only from verified owners. The vulnerability affects WordPress sites using the MStore API plugin, particularly those that allow product reviews.
Defensive priority
Defenders should prioritize patching the MStore API WordPress plugin to version 4.21.0 or later to prevent unauthorized product review creation.
Recommended defensive actions
- Patch the MStore API WordPress plugin to version 4.21.0 or later
- Monitor for suspicious product review activity
- Implement additional security controls to prevent unauthorized access
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
Evidence from the NVD and WPScan indicates that the MStore API WordPress plugin is vulnerable to unauthorized product review creation. However, detailed information about the vulnerability and its impact is limited. Defenders should verify the affected plugin version and review product review logs for suspicious activity. The CVE record was published on 2026-08-07T06:16:56.167Z and has not been modified since then.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-16041 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-16041
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-16041 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-16041
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpscan.com/vulnerability/0e7d8a17-0901-45b5-959c-2c1ef1316047/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.