CVE-2021-24148

Severity
9.8CRITICAL
EPSS
5.6%
top 9.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 18
Latest updateMay 24

Description

A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign In With Apple allowing unauthenticated users to recover an authentication cookie with only an email address.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

CVEListV5unknown/mstore_api3.2.03.2.0

🔴Vulnerability Details

2
GHSA
GHSA-99jg-2fvv-2jfq: A business logic issue in the MStore API WordPress plugin, versions before 32022-05-24
CVEList
MStore API < 3.2.0 - Authentication Bypass With Sign In With Apple2021-03-18
CVE-2021-24148 (CRITICAL CVSS 9.8) | A business logic issue in the MStor | cvebase.io