Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-16038: MStore API < 4.21.0 - Unauthenticated Payment Bypass via Multiple Gateways
CVE-2026-16038
CVE-2026-16038
Summary
The MStore API WordPress plugin allows an attacker to mark an order as paid without payment, potentially giving them free access to goods or services. This affects any sites using MStore API version 4.21.0 or earlier. To fix this, update the MStore API plugin to version 4.21.0 or later.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| unknown | mstore api | < 4.21.0 |
Original title
The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unaut...
Original description
The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its payment-completion endpoints, allowing an unauthenticated attacker to mark an arbitrary order fully paid without paying and obtain goods or services for free.
Vulnerability type
CWE-862
Missing Authorization
Published: 7 Aug 2026 · Updated: 7 Aug 2026 · First seen: 7 Aug 2026