CyberRota Analysis
AI-GeneratedThe MStore API WordPress plugin prior to version 4.21.0 is vulnerable as it fails to restrict access to the vendor-orders endpoint, allowing any authenticated user, including those with minimal permissions like Subscribers, to access all WooCommerce orders and associated customer personal information. This exposure can lead to significant data privacy breaches and unauthorized access to sensitive customer data. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential risks.
Original NVD Description
The MStore API WordPress plugin before 4.21.0 does not restrict its vendor-orders endpoint to the caller's own orders, allowing any authenticated user, including Subscribers, to read every WooCommerce order in the store together with each customer's personal information.