Description
The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a WordPress account and issuing a session, allowing unauthenticated attackers to log in as any user, including administrators.
Published: 2026-08-22
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated Account Takeover
Action: Patch Immediately
AI Analysis

Impact

The likely attack vector is via the plugin’s authentication endpoint, inferred from the fact it accepts tokens without verification. The Firebase Authentication WordPress plugin before version 1.7.1 accepts authentication tokens without first confirming that the email claim has been verified. An attacker can therefore craft a token containing any email address and present it to the plugin, which will match the claim to a WordPress user account and issue a session cookie. The result is that the attacker can log in as any user, including administrators, without holding valid credentials, giving full control over the site and its data.

Affected Systems

This flaw affects the Firebase Authentication WordPress plugin versions 1.0 through 1.6.x (that is, any release prior to 1.7.1). WordPress sites that have installed or activated this plugin are at risk. No other WordPress components are impacted.

Risk and Exploitability

Based on the description, it is inferred that the attack can be launched remotely via the plugin’s authentication endpoint. Given that the exploit requires only the creation of a well‑formed authentication token and does not rely on any additional privileges, the attack can be launched from any external network position. The lack of a public KEV listing does not diminish the inherent severity; being able to take over any account, including administrators, remains a critical threat. The CVSS base score of 8.1 indicates high severity, and the EPSS score of <1% means exploitation probability is low at present, but the impact of a successful exploit remains severe.

Generated by OpenCVE AI on August 23, 2026 at 19:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Firebase Authentication plugin to version 1.7.1 or later.
  • If the patch cannot be applied immediately, remove or deactivate the plugin and restrict administrative access until the upgrade is complete.
  • As a temporary measure, block or restrict access to the plugin’s authentication endpoint by configuring a firewall or WAF rule to reject requests containing an email claim that is not verified.

Generated by OpenCVE AI on August 23, 2026 at 19:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 23 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Sun, 23 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 22 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Sat, 22 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a WordPress account and issuing a session, allowing unauthenticated attackers to log in as any user, including administrators.
Title Firebase Authentication < 1.7.1 - Unauthenticated Account Takeover via Firebase Email Claim
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-23T15:33:41.354Z

Reserved: 2026-08-19T17:55:46.564Z

Link: CVE-2026-76793

cve-icon Vulnrichment

Updated: 2026-08-23T15:24:35.523Z

cve-icon NVD

Status : Deferred

Published: 2026-08-22T06:16:16.900

Modified: 2026-08-26T16:30:52.723

Link: CVE-2026-76793

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-23T20:00:06Z

Weaknesses