THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-13447 (CRITICAL 9.8) — The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_token() function, which decodes and validates

[NVD] CVE-2026-13447 (CRITICAL 9.8) — The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_token() function, which decodes and validates

mednvdPublished 2026-09-05

CVE-2026-13447 CVSS: 9.8 CRITICAL Published: 2026-09-05T06:17:09.403

The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_token() function, which decodes and validates Firebase ID token claims (alg, kid, aud, iss) but

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-13447