CVE-2026-16039 | MStore API Plugin up to 4.20.x on WordPress Vendor Orders Endpoint authorization

SecurityVulns

A vulnerability described as problematic has been identified in MStore API Plugin up to 4.20.x on WordPress. Impacted is an unknown function of the component Vendor Orders Endpoint. Such manipulation leads to authorization bypass.

This vulnerability is referenced as CVE-2026-16039. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is recommended.VulDB Recent EntriesRead More