Description
The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a token and take over that user's account, including administrator accounts.
Published: 2026-08-07
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The MStore API WordPress plugin fails to verify the cryptographic signature on Firebase phone authentication tokens. An attacker who knows a user’s phone number can forge a token, log in as that user, and gain full account privileges—including administrator rights—without any prior authentication.

Affected Systems

WordPress installations that use MStore API versions older than 4.21.0 are vulnerable. The weakness exists in every plugin build before the 4.21.0 release, regardless of site configuration.

Risk and Exploitability

The flaw allows unauthenticated attackers to take over any registered account by submitting a forged Firebase token. Exploitation requires only the victim’s phone number and the ability to construct the token, making the attack easy to execute. The CVSS score is 8.1, the EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog. Despite the low exploitation probability, the opportunity to obtain administrative control makes the risk severe.

Generated by OpenCVE AI on August 7, 2026 at 21:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the MStore API plugin to version 4.21.0 or later to enable proper signature verification of Firebase tokens.
  • If a timely upgrade cannot be performed, temporarily disable phone‑based authentication on the affected WordPress site until the plugin is updated.
  • After upgrading, reset passwords for all user accounts, especially administrators, and monitor authentication logs for signs of unauthorized access.

Generated by OpenCVE AI on August 7, 2026 at 21:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 08 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Mstore
Mstore mstore Api
Wordpress
Wordpress wordpress
Vendors & Products Mstore
Mstore mstore Api
Wordpress
Wordpress wordpress

Fri, 07 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-322
CWE-327

Fri, 07 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-322
CWE-327

Fri, 07 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a token and take over that user's account, including administrator accounts.
Title MStore API < 4.21.0 - Unauthenticated Account Takeover via Firebase Phone Authentication
References

Subscriptions

Mstore Mstore Api
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-07T17:39:59.872Z

Reserved: 2026-07-17T08:39:40.043Z

Link: CVE-2026-16030

cve-icon Vulnrichment

Updated: 2026-08-07T17:39:49.942Z

cve-icon NVD

Status : Deferred

Published: 2026-08-07T06:16:55.833

Modified: 2026-08-26T16:31:16.753

Link: CVE-2026-16030

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-08T20:53:31Z

Weaknesses