๐Ÿ” CVE Alert

CVE-2026-76793

UNKNOWN 0.0

Firebase Authentication < 1.7.1 - Unauthenticated Account Takeover via Firebase Email Claim

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a WordPress account and issuing a session, allowing unauthenticated attackers to log in as any user, including administrators.

Vendor unknown
Product firebase authentication
Published Aug 22, 2026
Stay Ahead of the Next One

Get instant alerts for unknown firebase authentication

Be the first to know when new unknown vulnerabilities affecting unknown firebase authentication are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Firebase Authentication
0 < 1.7.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/0414ef2b-0d97-41c7-9146-f31ace8b66b2/

Credits

Abdullah Kareem WPScan