---
id: CVE-2026-18233
title: >-
  The MStore API  WordPress plugin before 4.21.1 does not verify that the order
  targeted by one of its delivery endpoints belongs to the requester, allowing
  any authenticated user, including Subscribers, to mark arbitrary orders as
  complet…
summary: >-
  The MStore API  WordPress plugin before 4.21.1 does not verify that the order
  targeted by one of its delivery endpoints belongs to the requester, allowing
  any authenticated user, including Subscribers, to mark arbitrary orders as
  complet…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-862
published: '2026-08-29'
updated: '2026-08-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18233'
references:
  - url: 'https://wpscan.com/vulnerability/241c0394-8dfa-475c-a91b-e2b5e47add53/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00169
epssPercentile: 0.05549
ingestedAt: '2026-08-30T07:49:06.948Z'
---

## Overview

The MStore API  WordPress plugin before 4.21.1 does not verify that the order targeted by one of its delivery endpoints belongs to the requester, allowing any authenticated user, including Subscribers, to mark arbitrary orders as completed and paid without any payment being made.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
