Medium severity4.3NVD Advisory· Published May 27, 2025· Updated Jun 17, 2026
CVE-2025-4683
CVE-2025-4683
Description
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the create_blog function in all versions up to, and including, 4.17.5. This makes it possible for authenticated attackers, with Subscriber-level access and above, to create new posts.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- inspireui/MStore API – Create Native Android & iOS Apps On The Cloudv5Range: 0
Patches
Vulnerability mechanics
References
4- plugins.trac.wordpress.org/changeset/3293669/nvdPatch
- www.wordfence.com/threat-intel/vulnerabilities/id/b335bd15-7af7-4d8b-ad01-b1d9e76beb53nvdThird Party Advisory
- plugins.trac.wordpress.org/browser/mstore-api/tags/4.17.5/controllers/helpers/blog-helper.phpnvdProduct
- plugins.trac.wordpress.org/browser/mstore-api/tags/4.17.5/controllers/helpers/blog-helper.phpnvdProduct
News mentions
0No linked articles in our index yet.