Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

Plugin security history

MStore API – Create Native Android & iOS Apps On The Cloud Vulnerability History & Security Timeline

The Wordfence Intelligence dataset currently contains 31 vulnerability records associated with MStore API – Create Native Android & iOS Apps On The Cloud, published between 2020 and 2026.

Dataset last synchronized: 2026-08-03 00:31:25 UTC

At a glance

Security Snapshot

31Total records
12Critical
3High
16Medium
0Low
0Informational
31Patched records
0Currently marked unpatched
2020-03-11First disclosure
2026-07-07Latest disclosure
30 of 31CVE coverage

Year-by-Year Timeline

YearRecordsRelative volume
202011 records
202122 records
20231717 records
202466 records
202522 records
202633 records

Severity Breakdown

SeverityRecordsShare
Critical1238.7%
High39.7%
Medium1651.6%

Vulnerability-Type Breakdown

Authentication Bypass

8 records25.8%

First: 2020. Latest: 2024.

CSRF

7 records22.6%

First: 2023. Latest: 2023.

Missing Authorization

5 records16.1%

First: 2023. Latest: 2026.

SQL Injection

5 records16.1%

First: 2023. Latest: 2024.

Arbitrary File Upload

3 records9.7%

First: 2021. Latest: 2024.

Privilege Escalation

3 records9.7%

First: 2023. Latest: 2025.

Patch Status

Patched
31
Currently marked unpatched
0
Unknown status
0

Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.

Latest Known Patched Versions

  • 4.19.0
  • 4.18.4
  • 4.17.6
  • 4.17.5
  • 4.16.5
  • 4.15.8
  • 4.15.4
  • 4.15.3
  • 4.15.0
  • 4.10.2
  • 4.0.7
  • 4.0.2
  • 3.9.9
  • 3.9.8
  • 4.10.8
  • 3.9.7
  • 3.9.3
  • 3.9.2
  • 3.9.1
  • 3.4.5
  • 3.2.0
  • 2.1.6

Affected-Version History

Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.

Affected rangeVulnerabilityPublishedPatched versionSeverity
*-4.18.4MStore API – Create Native Android & iOS Apps On The Cloud <= 4.18.4 - Missing AuthorizationJuly 7, 20264.19.0Medium
*-4.18.4MStore API – Create Native Android & iOS Apps On The Cloud <= 4.18.4 - Missing AuthorizationJune 17, 20264.19.0Medium
*-4.18.3MStore API <= 4.18.3 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Meta UpdateApril 8, 20264.18.4Medium
*-4.17.5MStore API – Create Native Android & iOS Apps On The Cloud <= 4.17.5 - Missing Authorization to Authenticated (Subscriber+) Posts CreationMay 26, 20254.17.6Medium
*-4.17.4MStore API – Create Native Android & iOS Apps On The Cloud <= 4.17.4 - Unauthenticated Limited Privilege EscalationMay 1, 20254.17.5Medium
*-4.16.4MStore API – Create Native Android & iOS Apps On The Cloud <= 4.16.4 - Authenticated (Subscriber+) HTML File Upload (Stored Cross-Site Scripting)December 12, 20244.16.5Medium
*-4.15.7MStore API <= 4.15.7 - Authenticated (Subscriber+) SQL InjectionNovember 19, 20244.15.8Medium
*-4.15.3MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.3 - Authenticated (Subscriber+) Limited Arbitrary File UploadSeptember 12, 20244.15.4Medium
*-4.15.3MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.3 - Unauthorized User RegistrationSeptember 12, 20244.15.4High
*-4.15.2MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.2 - Authentication Bypass to Account TakeoverAugust 14, 20244.15.3High
*-4.14.7MStore API – Create Native Android & iOS Apps On The Cloud <= 4.14.7 - Authentication BypassJuly 11, 20244.15.0Critical
*-4.10.1MStore API <= 4.10.1 - Cross-Site Request ForgeryDecember 26, 20234.10.2Medium
*-4.0.6MStore API <= 4.0.6 - Authenticated (Subscriber+) SQL InjectionOctober 3, 20234.0.7High
*-4.0.1MStore API <= 4.0.1 - Unauthenticated SQL InjectionJune 23, 20234.0.2Critical
*-3.9.7MStore API <= 3.9.7 - Unauthenticated SQL InjectionJune 19, 20233.9.8Critical
*-3.9.8MStore API <= 3.9.8 - Unauthenticated Privilege EscalationJune 19, 20233.9.9Critical
*-3.9.7MStore API <= 3.9.7 - Unauthenticated SQL InjectionJune 19, 20233.9.8Critical
*-4.10.7MStore API <= 4.10.7 - Unauthorized Account Access and Privilege EscalationJune 19, 20234.10.8Critical
*-3.9.6MStore API <= 3.9.6 - Cross-Site Request Forgery to Firebase Server Key UpdateJune 13, 20233.9.7Medium
*-3.9.6MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Title UpdateJune 13, 20233.9.7Medium
*-3.9.6MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Status UpdateJune 13, 20233.9.7Medium
*-3.9.6MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Title UpdateJune 13, 20233.9.7Medium
*-3.9.6MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Message UpdateJune 13, 20233.9.7Medium
*-3.9.6MStore API <= 3.9.6 - Cross-Site Request Forgery to Product Limit UpdateJune 13, 20233.9.7Medium
[*, 3.9.7)MStore API <= 3.9.6 - Missing AuthorizationJune 12, 20233.9.7Medium

Selected source records

Latest Records

MediumCVE-2026-57375

MStore API – Create Native Android & iOS Apps On The Cloud <= 4.18.4 - Missing Authorization

Published: July 7, 2026

Affected versions
*-4.18.4
Patched versions
4.19.0
Original Wordfence record
MediumCVE-2026-54817

MStore API – Create Native Android & iOS Apps On The Cloud <= 4.18.4 - Missing Authorization

Published: June 17, 2026

Affected versions
*-4.18.4
Patched versions
4.19.0
Original Wordfence record
MediumCVE-2026-3568

MStore API <= 4.18.3 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Meta Update

Published: April 8, 2026

Affected versions
*-4.18.3
Patched versions
4.18.4
Original Wordfence record
MediumCVE-2025-4683

MStore API – Create Native Android & iOS Apps On The Cloud <= 4.17.5 - Missing Authorization to Authenticated (Subscriber+) Posts Creation

Published: May 26, 2025

Affected versions
*-4.17.5
Patched versions
4.17.6
Original Wordfence record
MediumCVE-2025-3438

MStore API – Create Native Android & iOS Apps On The Cloud <= 4.17.4 - Unauthenticated Limited Privilege Escalation

Published: May 1, 2025

Affected versions
*-4.17.4
Patched versions
4.17.5
Original Wordfence record
MediumCVE-2024-12042

MStore API – Create Native Android & iOS Apps On The Cloud <= 4.16.4 - Authenticated (Subscriber+) HTML File Upload (Stored Cross-Site Scripting)

Published: December 12, 2024

Affected versions
*-4.16.4
Patched versions
4.16.5
Original Wordfence record
MediumCVE-2024-11179

MStore API <= 4.15.7 - Authenticated (Subscriber+) SQL Injection

Published: November 19, 2024

Affected versions
*-4.15.7
Patched versions
4.15.8
Original Wordfence record
MediumCVE-2024-8242

MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.3 - Authenticated (Subscriber+) Limited Arbitrary File Upload

Published: September 12, 2024

Affected versions
*-4.15.3
Patched versions
4.15.4
Original Wordfence record

Highest-Severity Records

Critical

MStore API < 3.4.5 - Arbitrary File Upload

Published: October 5, 2021

Affected versions
[*, 3.4.5)
Patched versions
3.4.5
Original Wordfence record
CriticalCVE-2021-24148

MStore API <= 3.1.9 - Authentication Bypass

Published: February 2, 2021

Affected versions
*-3.1.9
Patched versions
3.2.0
Original Wordfence record
CriticalCVE-2024-6328

MStore API – Create Native Android & iOS Apps On The Cloud <= 4.14.7 - Authentication Bypass

Published: July 11, 2024

Affected versions
*-4.14.7
Patched versions
4.15.0
Original Wordfence record
CriticalCVE-2023-3277

MStore API <= 4.10.7 - Unauthorized Account Access and Privilege Escalation

Published: June 19, 2023

Affected versions
*-4.10.7
Patched versions
4.10.8
Original Wordfence record
CriticalCVE-2023-3197

MStore API <= 4.0.1 - Unauthenticated SQL Injection

Published: June 23, 2023

Affected versions
*-4.0.1
Patched versions
4.0.2
Original Wordfence record
CriticalCVE-2022-47614

MStore API <= 3.9.7 - Unauthenticated SQL Injection

Published: June 19, 2023

Affected versions
*-3.9.7
Patched versions
3.9.8
Original Wordfence record
CriticalCVE-2023-2734

MStore API <= 3.9.1 - Authentication Bypass

Published: May 22, 2023

Affected versions
*-3.9.1
Patched versions
3.9.2
Original Wordfence record
CriticalCVE-2023-3076

MStore API <= 3.9.8 - Unauthenticated Privilege Escalation

Published: June 19, 2023

Affected versions
*-3.9.8
Patched versions
3.9.9
Original Wordfence record

View all associated vulnerabilities

Need help reviewing an exposed WordPress website?

Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.

Return to the Security History Directory