---
id: CVE-2026-18234
title: >-
  The MStore API  WordPress plugin before 4.21.1 does not verify that the order
  targeted by its wallet payment handling belongs to the requester, and does not
  deduct the wallet balance for most payment methods, allowing any authenticated
  u…
summary: >-
  The MStore API  WordPress plugin before 4.21.1 does not verify that the order
  targeted by its wallet payment handling belongs to the requester, and does not
  deduct the wallet balance for most payment methods, allowing any authenticated
  u…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-862
published: '2026-08-29'
updated: '2026-08-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18234'
references:
  - url: 'https://wpscan.com/vulnerability/1dc31c4e-9687-4056-a93e-9509c5a88828/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00169
epssPercentile: 0.0555
ingestedAt: '2026-08-30T07:49:07.004Z'
---

## Overview

The MStore API  WordPress plugin before 4.21.1 does not verify that the order targeted by its wallet payment handling belongs to the requester, and does not deduct the wallet balance for most payment methods, allowing any authenticated user, including Subscribers, to mark arbitrary orders as paid without any payment being taken.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
