The MStore API WordPress plugin before version 3.9.9 contains a vulnerability in its wholesale REST API endpoint that allows unauthenticated visitors to create user accounts with arbitrary roles. This flaw is present only if the site owner has enabled the plugin's pro features. The vulnerability arises from insufficient access control and validation in the REST API endpoint, allowing attackers to specify any user role during account creation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides an automated Bash script (msaper.sh) to exploit CVE-2023-3076, a critical unauthenticated privilege escalation and file upload vulnerability in the MStore API WordPress plugin (versions <3.9.9). The script is designed for mass exploitation, taking a list of target URLs (list.txt) and using GNU Parallel to process multiple targets concurrently. For each target, it checks the plugin version, attempts to create a new administrator user via a vulnerable API endpoint, and tries to upload a PHP file for further exploitation. Results are logged in separate files for vulnerable, non-vulnerable, and successfully exploited sites. The repository is operational and ready for use, requiring only Bash and GNU Parallel. No fake or detection-only code is present; the script is a real exploit with working payloads.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.