CVE-2026-16030: MStore API < 4.21.0 - Unauthenticated Account Takeover via Firebase Phone Authentication
The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a token and take over that user's account, including administrator accounts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16030?
CVE-2026-16030 has a risk score of 89, indicating a critical vulnerability.
How do I fix CVE-2026-16030?
To fix CVE-2026-16030, update the MStore API WordPress plugin to version 4.21.0 or later.
What type of attack does CVE-2026-16030 enable?
CVE-2026-16030 enables unauthenticated account takeover via Firebase Phone Authentication.
What software is affected by CVE-2026-16030?
CVE-2026-16030 affects the MStore API WordPress plugin prior to version 4.21.0.
Who is at risk from CVE-2026-16030?
Users of the MStore API WordPress plugin who have phone-based login enabled and have registered phone numbers are at risk from CVE-2026-16030.