CVE-2026-16030
MStore API < 4.21.0 - Unauthenticated Account Takeover via Firebase Phone Authentication
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a token and take over that user's account, including administrator accounts.
| Vendor | unknown |
| Product | mstore api |
| Published | Aug 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown mstore api
Be the first to know when new unknown vulnerabilities affecting unknown mstore api are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / MStore API
0 < 4.21.0
References
Credits
Sai Praneeth Koti WPScan