CVE-2025-11127: Unknown Mstoreapp Mobile App
Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.
The Mstoreapp Mobile App WordPress plugin through 2.08 and Mstoreapp Mobile Multivendor through 9.0.1 do not properly verify users identify when using an AJAX action, allowing unauthenticated users to retrieve a valid session for arbitrary users by knowing their email address.
Affected products
- Unknown Mstoreapp Mobile App: up to and including 2.0.8
- Unknown Mstoreapp Mobile Multivendor: up to and including 9.0.1
Published 2025-11-21. Last modified 2026-06-17.