THREAT OPS › Threat News › [NVD] CVE-2026-13447 (CRITICAL 9.8) — The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_token() function, which decodes and validates
[NVD] CVE-2026-13447 (CRITICAL 9.8) — The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_token() function, which decodes and validates
CVE-2026-13447 CVSS: 9.8 CRITICAL Published: 2026-09-05T06:17:09.403
The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_token() function, which decodes and validates Firebase ID token claims (alg, kid, aud, iss) but
Indicators of compromise
- CVE-2026-13447cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-13447