EXPOSURES › CVE-2026-13447
CVE-2026-13447
CRITICALThe Mstore Api WordPress plugin allows unauthenticated attackers to forge Firebase Phone Auth JWTs and impersonate any phone number due to missing cryptographic signature verification.
The Mstore Api WordPress plugin failed to validate JWT signatures when verifying Firebase ID tokens, enabling attackers to forge authentication tokens and impersonate any phone number. This authentication bypass allows unauthenticated access to existing WordPress accounts or creation of arbitrary new accounts, directly violating CMMC/NIST 800-171 requirements for access control and authentication. DIB organizations must ensure all WordPress plugins are patched and that JWT implementations strictly validate cryptographic signatures against trusted public keys.
Shame score — A critical authentication bypass in a widely used WordPress plugin that allows unauthenticated attackers to forge phone authentication tokens and impersonate any user, representing a severe avoidable failure in cryptographic implementation.
▸ RECOMMENDED ACTION Critical severity — schedule patching of the affected products.
The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_token() function, which decodes and validates Firebase ID token claims (alg, kid, aud, iss) but never calls openssl_verify() or any equivalent to validate the JWT signature against Google's actual public key certificates. This makes it possible for unauthenticated attackers to forge a Firebase Phone Auth JWT signed with a self-generated RSA key pair and impersonate any phone number, resulting in unauthorized access to existing WordPress accounts or creation of new arbitrary accounts.