{ "id": "CVE-2023-3131", "sourceIdentifier": "contact@wpscan.com", "published": "2023-07-10T16:15:55.080", "lastModified": "2023-07-10T16:27:17.833", "vulnStatus": "Awaiting Analysis", "descriptions": [ { "lang": "en", "value": "The MStore API WordPress plugin before 3.9.7 does not secure most of its AJAX actions by implementing privilege checks, nonce checks, or a combination of both." } ], "metrics": {}, "weaknesses": [ { "source": "contact@wpscan.com", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-862" } ] } ], "references": [ { "url": "https://wpscan.com/vulnerability/970735f1-24bb-441c-89b6-5a0959246d6c", "source": "contact@wpscan.com" } ] }