PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-16041 MStore API CVE debrief

The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chosen reviewer name, email and star rating on stores configured to accept reviews only from verified owners.

Vendor
MStore API
Product
MStore API WordPress plugin
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-07
Original CVE updated
2026-08-26
Advisory published
2026-08-07
Advisory updated
2026-08-26

Who should care

Administrators of WordPress sites using the MStore API plugin should be aware of this vulnerability and take steps to patch it. Additionally, security teams monitoring for suspicious product review activity may want to investigate this vulnerability further. Site owners and security personnel responsible for maintaining WordPress installations should prioritize patching the plugin to prevent exploitation. Security teams may also want to review product review logs for potential malicious activity related to this vulnerability. IT managers overseeing WordPress deployments should ensure that the MStore API plugin is updated to version 4.21.0 or later to mitigate the risk of unauthorized product review creation. Compliance teams may also want to assess the potential impact of this vulnerability on their organization's risk profile and ensure that appropriate measures are taken to protect against exploitation. Furthermore, incident response teams should be prepared to investigate and respond to potential security incidents related to this vulnerability. Lastly, developers and DevOps teams should consider implementing additional security controls, such as monitoring and logging, to detect and prevent potential attacks. Security awareness training for personnel responsible for WordPress site management and security may also be beneficial in preventing similar vulnerabilities from being exploited in the future. Lastly, external security auditors may want to include this vulnerability in their risk assessments and penetration testing activities to ensure that organizations are adequately protected against exploitation. The MStore API plugin's vulnerability highlights the importance of robust security measures and proactive vulnerability management in WordPress deployments. By prioritizing patching and implementing additional security controls, organizations can reduce the risk of exploitation and protect their WordPress sites from potential attacks. Overall, a comprehensive approach to security and vulnerability management is essential in mitigating the risks associated with this vulnerability and ensuring the security of WordPress deployments. The vulnerability's impact

Technical summary

The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route. This allows an unauthenticated attacker to create WooCommerce product reviews with an attacker-chosen reviewer name, email, and star rating on stores configured to accept reviews only from verified owners. The vulnerability affects WordPress sites using the MStore API plugin, particularly those that allow product reviews.

Defensive priority

Defenders should prioritize patching the MStore API WordPress plugin to version 4.21.0 or later to prevent unauthorized product review creation.

Recommended defensive actions

  • Patch the MStore API WordPress plugin to version 4.21.0 or later
  • Monitor for suspicious product review activity
  • Implement additional security controls to prevent unauthorized access
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

Evidence from the NVD and WPScan indicates that the MStore API WordPress plugin is vulnerable to unauthorized product review creation. However, detailed information about the vulnerability and its impact is limited. Defenders should verify the affected plugin version and review product review logs for suspicious activity. The CVE record was published on 2026-08-07T06:16:56.167Z and has not been modified since then.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-16041 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-16041

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-16041 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-16041

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.