PT-2026-86308 · WordPress · Mstore Api

·

CVE-2026-13447

·

Published

2026-09-05

·

Updated

2026-09-06

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mstore Api plugin for WordPress versions prior to 4.20.1
Description An authentication bypass exists due to JWT (JSON Web Token) forgery. The issue occurs in the FirebasePhoneAuthHelper::verify id token() function, which validates token claims such as alg, kid, aud, and iss but fails to perform cryptographic signature verification using openssl verify() or an equivalent method against Google's public key certificates. This allows unauthenticated attackers to use a self-generated RSA key pair to forge a Firebase Phone Auth JWT and impersonate any phone number, leading to unauthorized access to existing accounts or the creation of arbitrary new accounts.
Recommendations Update the Mstore Api plugin for WordPress to a version newer than 4.20.0.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13447

Affected Products

Mstore Api