Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 24 Nov 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Fri, 21 Nov 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 21 Nov 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Mstoreapp Mobile App WordPress plugin through 2.08 and Mstoreapp Mobile Multivendor through 9.0.1 do not properly verify users identify when using an AJAX action, allowing unauthenticated users to retrieve a valid session for arbitrary users by knowing their email address. | |
| Title | Mstoreapp Mobile (App <= 2.08, Multivendor <= 9.0.1) - Unauthenticated Privilege Escalation | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-11-21T14:23:36.421Z
Reserved: 2025-09-27T19:41:26.193Z
Link: CVE-2025-11127
Updated: 2025-11-21T14:23:32.881Z
Status : Deferred
Published: 2025-11-21T14:15:59.057
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-11127
No data.
OpenCVE Enrichment
Updated: 2025-11-24T09:08:33Z
No weakness.