This issue affects MStore API: from n/a through 4.18.4.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update the WordPress MStore API Plugin to the latest available version (at least 4.19.0).
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 18 Jun 2026 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fluxbuilder
Fluxbuilder mstore Api Wordpress Wordpress wordpress |
|
| Vendors & Products |
Fluxbuilder
Fluxbuilder mstore Api Wordpress Wordpress wordpress |
|
| Metrics |
ssvc
|
Wed, 17 Jun 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recovery Exploitation. This issue affects MStore API: from n/a through 4.18.4. | |
| Title | WordPress MStore API plugin <= 4.18.4 - Broken Authentication vulnerability | |
| Weaknesses | CWE-288 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Patchstack
Published:
Updated: 2026-06-17T14:15:18.655Z
Reserved: 2026-06-16T09:21:46.612Z
Link: CVE-2026-54817
Updated: 2026-06-17T14:14:54.538Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-18T14:00:16Z