PT-2026-86308 · WordPress · Mstore Api
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Mstore Api plugin for WordPress versions prior to 4.20.1
Description
An authentication bypass exists due to JWT (JSON Web Token) forgery. The issue occurs in the
FirebasePhoneAuthHelper::verify id token() function, which validates token claims such as alg, kid, aud, and iss but fails to perform cryptographic signature verification using openssl verify() or an equivalent method against Google's public key certificates. This allows unauthenticated attackers to use a self-generated RSA key pair to forge a Firebase Phone Auth JWT and impersonate any phone number, leading to unauthorized access to existing accounts or the creation of arbitrary new accounts.Recommendations
Update the Mstore Api plugin for WordPress to a version newer than 4.20.0.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mstore Api