CVE-2026-18234

The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by its wallet payment handling belongs to the requester, and does not deduct the wallet balance for most payment methods, allowing any authenticated user, including Subscribers, to mark arbitrary orders as paid without any payment being taken.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-29 06:17

Updated : 2026-08-31 20:14


NVD link : CVE-2026-18234

Mitre link : CVE-2026-18234

CVE.ORG link : CVE-2026-18234


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization