cvedb.io
CVE-2026-16041
HIGH · CVSS 7.5
EPSS exploitation probability: 0%
Published 2026-08-07T06:16:56.167 · Last modified 2026-08-07T19:17:36.343

Summary

The MStore API WordPress plugin before 4.21.0 does not perform authorization or purchase-ownership checks on its REST product-review creation route, allowing an unauthenticated attacker to create WooCommerce product reviews with an attacker-chosen reviewer name, email and star rating on stores configured to accept reviews only from verified owners.

Does this affect you?

Add your gear to cvedb and we'll alert you only when a vendor you run ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.