Inspireui maintains a narrowly focused product portfolio centered on the mStore API, a mobile commerce and e-commerce backend platform that, despite modest volume, occupies a prominent position in the vulnerability landscape through its role in payment and order-handling workflows. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit tooling, creating meaningful risk for deployments that depend on the platform for transaction processing. The exposure recurs persistently through authentication and authorization weaknesses—including authentication bypass via alternate channels, CSRF, SQL injection, and missing authorization checks—that are characteristic of API-layer flaws in systems handling sensitive commerce data. Defenders should prioritize patches for this vendor's disclosures and audit exposed instances for authentication controls and input validation; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Inspireui over time
Signals from CVEs in this vendor scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-2732CRITICAL The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.2. This is due to insufficient verification on the user being suppl | May 25, 2023 | 9.8 | 77 | NO | YES |
CVE-2023-3277CRITICAL The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, and including, 4.10.7 due to improper implementation of | Nov 3, 2023 | 9.8 | 44 | NO | YES |
CVE-2023-3077CRITICAL The MStore API WordPress plugin before 3.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to a Blind SQL injection exploitable by unauthenti | Jul 10, 2023 | 9.8 | 41 | NO | YES |
CVE-2023-2734CRITICAL The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.1. This is due to insufficient verification on the user being suppl | May 25, 2023 | 9.8 | 41 | NO | YES |
CVE-2023-3197CRITICAL The MStore API plugin for WordPress is vulnerable to Unauthenticated Blind SQL Injection via the 'id' parameter in versions up to, and including, 4.0.1 due to insufficient escaping | Jun 24, 2023 | 9.8 | 40 | NO | YES |
CVE-2023-3076CRITICAL The MStore API WordPress plugin before 3.9.9 does not prevent visitors from creating user accounts with the role of their choice via their wholesale REST API endpoint. This is only | Jul 10, 2023 | 9.8 | 31 | NO | NO |
CVE-2023-2733CRITICAL The MStore API plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.9.0. This is due to insufficient verification on the user being suppl | May 25, 2023 | 9.8 | 31 | NO | NO |
CVE-2021-24148CRITICAL A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign In With Apple allowing unauthenticated users to recover an | Mar 18, 2021 | 9.8 | 29 | NO | NO |
CVE-2024-6328CRITICAL The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 4.14.7. This is due | Jul 12, 2024 | 9.8 | 28 | NO | NO |
CVE-2023-45055CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in InspireUI MStore API allows SQL Injection.This issue affects MStore API: from | Nov 6, 2023 | 9.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (28 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Inspireui.
Media articles that mention a CVE ID that affects a product developed by Inspireui — matched by CVE ID, not by vendor name.