CVE-2026-76793
Firebase Authentication < 1.7.1 - Unauthenticated Account Takeover via Firebase Email Claim
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a WordPress account and issuing a session, allowing unauthenticated attackers to log in as any user, including administrators.
| Vendor | unknown |
| Product | firebase authentication |
| Published | Aug 22, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown firebase authentication
Be the first to know when new unknown vulnerabilities affecting unknown firebase authentication are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Firebase Authentication
0 < 1.7.1
References
Credits
Abdullah Kareem WPScan