CVE-2021-24148

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
18/03/2021
Last modified:
23/03/2021

Description

A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign In With Apple allowing unauthenticated users to recover an authentication cookie with only an email address.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:inspireui:mstore_api:*:*:*:*:*:wordpress:*:* 3.2.0 (excluding)