AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-16041

HIGH · CVSS 7.5 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The MStore API plugin for WordPress prior to version 4.21.0 is vulnerable due to a lack of authorization checks on its REST product-review creation route, enabling unauthenticated attackers to submit fraudulent WooCommerce product reviews. This could lead to the manipulation of product ratings and damage to store reputation, particularly for stores that restrict reviews to verified owners. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-16041
Severity
HIGH
CVSS
7.5
EPSS
0.21%
WordPress

Original NVD Description

The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chosen reviewer name, email and star rating on stores configured to accept reviews only from verified owners.