Impact
The MStore API WordPress plugin fails to verify the cryptographic signature on Firebase phone authentication tokens. An attacker who knows a user’s phone number can forge a token, log in as that user, and gain full account privileges—including administrator rights—without any prior authentication.
Affected Systems
WordPress installations that use MStore API versions older than 4.21.0 are vulnerable. The weakness exists in every plugin build before the 4.21.0 release, regardless of site configuration.
Risk and Exploitability
The flaw allows unauthenticated attackers to take over any registered account by submitting a forged Firebase token. Exploitation requires only the victim’s phone number and the ability to construct the token, making the attack easy to execute. The CVSS score is 8.1, the EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog. Despite the low exploitation probability, the opportunity to obtain administrative control makes the risk severe.
OpenCVE Enrichment