CVE-2023-2732 is an authentication bypass vulnerability in the MStore API plugin for WordPress, affecting versions up to and including 3.9.2. The vulnerability arises from insufficient verification of the user identity during the add listing REST API request, allowing an attacker to specify any user ID and gain access as that user, including administrators.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a Python exploit script (mstore-api.py) targeting CVE-2023-2732, an authentication bypass vulnerability in the MStore API WordPress plugin (versions <= 3.9.2). The exploit works by first checking the plugin version via the readme.txt file, then enumerating users through the REST API, and finally sending a crafted GET request to the /wp-json/wp/v2/add-listing endpoint with a chosen user ID. If successful, the attacker receives a valid WordPress session as the targeted user, effectively bypassing authentication. The script is operational and automates the exploitation process, requiring only the target site URL as input. The repository also includes a README with usage instructions and a requirements.txt listing dependencies (click, requests). No framework is used; the exploit is standalone Python code.
This repository contains a Python 2.7 script (CVE-2023-2732.py) and a README.md. The script is a proof-of-concept exploit for CVE-2023-2732, targeting WordPress sites. It takes a list of target domains, enumerates user IDs via the /wp-json/wp/v2/users endpoint, and attempts to access /wp-json/wp/v2/add-listing?id=<user_id> to retrieve authentication cookies. If successful, it provides URLs that may allow further exploitation or access to the WordPress admin panel. The script uses multithreading for mass exploitation and writes results to a file. The README provides basic usage information and references. No weaponized payload is included; the script is primarily for enumeration and initial access testing.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.