{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/mstore/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:mstore:mstore_api:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-13447"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Mstore Api (\u003c= 4.20.0)"],"_cs_severities":["critical"],"_cs_tags":["wordpress","cve","authentication-bypass","web-application"],"_cs_type":"advisory","_cs_vendors":["Mstore"],"content_html":"\u003cp\u003eThe Mstore Api plugin for WordPress is susceptible to an authentication bypass vulnerability, tracked as CVE-2026-13447, affecting all versions up to and including 4.20.0. The vulnerability resides in the FirebasePhoneAuthHelper::verify_id_token() function, which is responsible for validating Firebase identity tokens. The implementation properly decodes JWT claims such as 'alg', 'kid', 'aud', and 'iss', but completely fails to perform cryptographic signature verification. Specifically, the function neglects to call openssl_verify() or utilize any mechanism to validate the token against Google's public key infrastructure. Consequently, an unauthenticated attacker can supply a forged JWT signed with a custom RSA key pair, effectively bypassing authentication checks. This allows for unauthorized access to existing WordPress user accounts associated with specific phone numbers or the creation of new, arbitrary accounts with elevated privileges.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a WordPress site utilizing the Mstore Api plugin version 4.20.0 or earlier.\u003c/li\u003e\n\u003cli\u003eAttacker interacts with the plugin authentication endpoint that triggers the FirebasePhoneAuthHelper::verify_id_token() function.\u003c/li\u003e\n\u003cli\u003eAttacker generates a custom RSA key pair to sign a malicious JWT.\u003c/li\u003e\n\u003cli\u003eAttacker constructs a forged JWT with claims matching the target user or arbitrary account details.\u003c/li\u003e\n\u003cli\u003eAttacker transmits the forged JWT to the vulnerable plugin endpoint.\u003c/li\u003e\n\u003cli\u003eThe plugin logic decodes the provided JWT and validates claims, but skips signature verification, accepting the forged token as valid.\u003c/li\u003e\n\u003cli\u003eThe plugin grants the attacker an authenticated session context for the impersonated identity.\u003c/li\u003e\n\u003cli\u003eAttacker gains unauthorized access to the victim's account data or account creation functionality.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation enables unauthenticated remote attackers to bypass identity verification, leading to account takeover or the unauthorized creation of arbitrary user accounts. This grants attackers access to sensitive user data and administrative functions within the WordPress environment. The 9.8 CVSS score reflects the high potential for full compromise of user accounts and the relative ease of generating forged tokens due to the total absence of cryptographic validation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the Mstore Api plugin to the latest available version beyond 4.20.0 to remediate CVE-2026-13447.\u003c/li\u003e\n\u003cli\u003eAudit access logs for suspicious account authentication patterns or unexpected account creations tied to phone-based registration workflows.\u003c/li\u003e\n\u003cli\u003eIf the latest patch cannot be applied, disable the plugin to eliminate the vulnerable endpoint from the attack surface.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-05T07:29:49Z","date_published":"2026-09-05T07:29:49Z","id":"https://feed.craftedsignal.io/briefs/2026-09-mstore-api-auth-bypass/","summary":"The Mstore Api plugin for WordPress (\u003c= 4.20.0) is vulnerable to authentication bypass via JWT forgery, allowing unauthenticated attackers to impersonate any user by crafting illegitimate Firebase Phone Auth tokens.","title":"Authentication Bypass in Mstore Api Plugin for WordPress via JWT Forgery","url":"https://feed.craftedsignal.io/briefs/2026-09-mstore-api-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Mstore","version":"https://jsonfeed.org/version/1.1"}