Critical CVSS: CRITICAL CVE-2023-3277 vulnerability

CVE-2023-3277: The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access

Tracked since May 6, 2026 View on NVD

CVSS Breakdown

9.8
CVSS Base Score
CRITICAL
Attack Vector
N/A
Requires physical access to exploit.
CIA Impact
Confidentiality N/A
Integrity N/A
Availability N/A

Insurance Impact Assessment

🛡️
Critical Impact

Critical vulnerabilities require urgent remediation. Insurers may impose coverage conditions, increased retentions, or exclusion endorsements until patches are applied.

CVE CVE-2023-3277 with CVSS 9.8. The MStore API plugin for WordPress is vulnerable to Unauthorized Account Access and Privilege Escalation in versions up to, and including, 4.10.7 due to improper implementation of the Apple login feature. This allows unauthenticated attackers to log in as any user as long as they know the user's em

View on NVD

Assess your exposure

Is your organization vulnerable? Run a free domain exposure scan to check.

← Back to Threat Feed