Impact
The MStore API WordPress plugin does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login. An attacker who knows a registered user's phone number can forge a token and impersonate that user, gaining account privileges – including administrator rights – without any authentication.
Affected Systems
WordPress sites that use the MStore API plugin older than version 4.21.0 are vulnerable. All installations of the plugin prior to 4.21.0 lack the necessary signature verification for Firebase phone authentication.
Risk and Exploitability
The vulnerability permits unauthenticated attackers to take over any user account by submitting a forged Firebase token. No credentials or privileged access are required beyond the target phone number. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, but the potential impact is severe because it leads directly to full account takeover, including administrative control. The attack requires only knowledge of a phone number and the ability to construct a valid token, making exploitation theoretically straightforward and dangerous.
OpenCVE Enrichment