CVE-2025-3438: Inspireui Mstore API

High severity, CVSS 7.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 4.17.4. This is due to a lack of restriction of role when registering. This makes it possible for unauthenticated attackers to to register with the 'wcfm_vendor' role, which is a Store Vendor role in the WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress. The vulnerability can only be exploited if the WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin is installed and activated. The vulnerability was partially patched in version 4.17.3.

Affected products

  • Inspireui Mstore API: before 4.17.5 (fixed in 4.17.5)

Published 2025-05-02. Last modified 2026-06-17.