
MStore API – Create Native Android & iOS Apps On The Cloud Security & Risk Analysis
wordpress.org/plugins/mstore-apiTake your WordPress store mobile with MStore API! This plugin bridges the gap between your WordPress website and the powerful FluxBuilder app builder.
Is MStore API – Create Native Android & iOS Apps On The Cloud Safe to Use in 2026?
Mostly Safe
Score 76/100MStore API – Create Native Android & iOS Apps On The Cloud is generally safe to use. 29 past CVEs were resolved.
The mstore-api v4.18.3 plugin presents a mixed security posture. While it demonstrates strong practices in areas like SQL query preparation (100% prepared) and output escaping (97%), significant concerns arise from its attack surface and historical vulnerability data. The presence of 3 unprotected AJAX handlers is a critical oversight that could lead to unauthorized actions or privilege escalation. The taint analysis, while showing no critical or high severity flows, did reveal 2 flows with unsanitized paths, which, if exploitable, could still pose a risk. The plugin's extensive vulnerability history, with 28 known CVEs including 12 critical ones, is a major red flag. The common types of vulnerabilities observed (Improper Privilege Management, Missing Authorization, SQL Injection, CSRF, Authentication Bypass) indicate recurring systemic issues with access control and input validation within the plugin's development. Despite improvements in specific coding practices, the sheer volume and severity of past vulnerabilities suggest that fundamental security flaws may persist and new ones could emerge, especially considering the unprotected entry points identified. This plugin requires careful scrutiny and ongoing monitoring.
Key Concerns
- 3 unprotected AJAX handlers
- 2 flows with unsanitized paths
- 28 total known CVEs
- 12 critical severity CVEs
- Common vuln types: Improper Privilege Management
- Common vuln types: Missing Authorization
- Common vuln types: SQL Injection
- Common vuln types: CSRF
- Common vuln types: Authentication Bypass
MStore API – Create Native Android & iOS Apps On The Cloud Security Vulnerabilities
CVEs by Year
Severity Breakdown
29 total CVEs
MStore API <= 4.18.3 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary User Meta Update
MStore API – Create Native Android & iOS Apps On The Cloud <= 4.17.5 - Missing Authorization to Authenticated (Subscriber+) Posts Creation
MStore API – Create Native Android & iOS Apps On The Cloud <= 4.17.4 - Unauthenticated Limited Privilege Escalation
MStore API – Create Native Android & iOS Apps On The Cloud <= 4.16.4 - Authenticated (Subscriber+) HTML File Upload (Stored Cross-Site Scripting)
MStore API <= 4.15.7 - Authenticated (Subscriber+) SQL Injection
MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.3 - Authenticated (Subscriber+) Limited Arbitrary File Upload
MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.3 - Unauthorized User Registration
MStore API – Create Native Android & iOS Apps On The Cloud <= 4.15.2 - Authentication Bypass to Account Takeover
MStore API – Create Native Android & iOS Apps On The Cloud <= 4.14.7 - Authentication Bypass
MStore API <= 4.10.1 - Cross-Site Request Forgery
MStore API <= 4.0.6 - Authenticated (Subscriber+) SQL Injection
MStore API <= 4.0.1 - Unauthenticated SQL Injection
MStore API <= 4.10.7 - Unauthorized Account Access and Privilege Escalation
MStore API <= 3.9.7 - Unauthenticated SQL Injection
MStore API <= 3.9.8 - Unauthenticated Privilege Escalation
MStore API <= 3.9.7 - Unauthenticated SQL Injection
MStore API <= 3.9.6 - Cross-Site Request Forgery to Product Limit Update
MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Message Update
MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Title Update
MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Status Update
MStore API <= 3.9.6 - Cross-Site Request Forgery to Order Title Update
MStore API <= 3.9.6 - Cross-Site Request Forgery to Firebase Server Key Update
MStore API <= 3.9.6 - Missing Authorization
MStore API <= 3.9.2 - Authentication Bypass
MStore API <= 3.9.1 - Authentication Bypass
MStore API <= 3.9.0 - Authentication Bypass
MStore API < 3.4.5 - Arbitrary File Upload
MStore API <= 3.1.9 - Authentication Bypass
MStore API <= 2.1.5 - Authentication Bypass
MStore API – Create Native Android & iOS Apps On The Cloud Release Timeline
MStore API – Create Native Android & iOS Apps On The Cloud Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
MStore API – Create Native Android & iOS Apps On The Cloud Attack Surface
AJAX Handlers 8
REST API Routes 26
WordPress Hooks 130
Maintenance & Trust
MStore API – Create Native Android & iOS Apps On The Cloud Maintenance & Trust
Maintenance Signals
Community Trust
MStore API – Create Native Android & iOS Apps On The Cloud Alternatives
WappPress – Convert Site to App Fast – WordPress to Mobile App Builder
wapppress-builds-android-app-for-website
Short Description:Convert your website into Mobile App in just one click – no coding needed. Instantly generate an APK or AAB.
Mobile App Editor – WordPress to Android App Builder
mobile-app-editor
Native Android App Builder for wordpress and woocommerce.
Taqnix
taqnix
Build AI-powered mobile apps for WordPress/WooCommerce. No code, 100+ templates, push alerts, payments. Launch in minutes.
My FastAPP
my-fastapp
Create your native Android/iOS app using a wordpress admin console.
TC Ecommerce – Create Android & iOS Apps for WooCommerce
tc-ecommerce
TC eCommerce Plugin is complete mobile app solution for android and iOS platform with WordPress WooCommerce as backend.
MStore API – Create Native Android & iOS Apps On The Cloud Developer Profile
1 plugin · 3K total installs
How We Detect MStore API – Create Native Android & iOS Apps On The Cloud
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mstore-api/assets/css/common.css/wp-content/plugins/mstore-api/assets/css/header.css/wp-content/plugins/mstore-api/assets/css/styles.css/wp-content/plugins/mstore-api/assets/js/common.js/wp-content/plugins/mstore-api/assets/js/custom.js/wp-content/plugins/mstore-api/assets/js/mstore-api.js/wp-content/plugins/mstore-api/assets/js/scripts.js/wp-content/plugins/mstore-api/assets/js/common.js/wp-content/plugins/mstore-api/assets/js/custom.js/wp-content/plugins/mstore-api/assets/js/mstore-api.js/wp-content/plugins/mstore-api/assets/js/scripts.jsmstore-api/assets/css/common.css?ver=mstore-api/assets/css/header.css?ver=mstore-api/assets/css/styles.css?ver=mstore-api/assets/js/common.js?ver=mstore-api/assets/js/custom.js?ver=mstore-api/assets/js/mstore-api.js?ver=mstore-api/assets/js/scripts.js?ver=HTML / DOM Fingerprints
mstore-api-wrappermstore-api-headermstore-api-footermstore-api-product-itemMStore API PluginMStore Checkoutdata-mstore-iddata-mstore-product-idMStoreApimstore_ajax_url/wp-json/mstore/api/v1/products/wp-json/mstore/api/v1/categories/wp-json/mstore/api/v1/cart[mstore_api_products][mstore_api_categories][mstore_api_cart]