MStore API plugin for WordPress up to version 4.0.1 contains an unauthenticated blind SQL injection caused by insufficient escaping of 'id' parameter in SQL queries, letting attackers execute arbitrary SQL commands without authentication, exploit requires sending crafted requests with malicious 'id' parameter.
id: CVE-2023-3197
info:
name: WordPress MStore API <= 4.0.1 - Unauthenticated SQL Injection
aut
...