PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-16030 MStore API CVE debrief

The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a token and take over that user's account, including administrator accounts. This vulnerability has significant implications for WordPress site administrators and security teams, as it could lead to unauthorized account takeovers. Affected deployments should be verified, and administrators should review official advisories and plan for vendor-supported updates or mitigations. Evidence from WPScan and official CVE records supports this assessment. Defenders should prioritize securing their deployments, reviewing plugin versions, and implementing additional authentication mechanisms where necessary.

Vendor
MStore API
Product
MStore API WordPress plugin
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-07
Original CVE updated
2026-08-26
Advisory published
2026-08-07
Advisory updated
2026-08-26

Who should care

WordPress site administrators using the MStore API plugin, security teams monitoring for potential account takeover vulnerabilities, users with administrator accounts on affected sites, and operators managing WordPress environments should review and take action to secure their deployments.

Technical summary

The MStore API WordPress plugin before 4.21.0 is vulnerable due to its improper verification of the cryptographic signature of tokens used for phone-based login authentication. This flaw enables unauthenticated attackers with knowledge of a registered user's phone number to forge tokens and gain unauthorized access to user accounts, including those with administrator privileges. The vulnerability is characterized by a high CVSS score of 8.1, indicating a high severity level. To address this issue, it is crucial for administrators to update the MStore API plugin to version 4.21.0 or later, implement additional authentication mechanisms for phone-based logins, monitor for suspicious account activities, and restrict access to sensitive areas of the WordPress site. Regular reviews and updates of WordPress plugins and themes are also recommended to mitigate potential risks.

Defensive priority

High priority due to high CVSS score of 8.1 and potential for account takeover.

Recommended defensive actions

  • Update MStore API WordPress plugin to version 4.21.0 or later
  • Implement additional authentication mechanisms for phone-based login
  • Monitor for suspicious account activity
  • Restrict access to sensitive areas of the WordPress site
  • Regularly review and update WordPress plugins and themes

Evidence notes

Evidence from WPScan indicates a vulnerability in the MStore API WordPress plugin. Official CVE and NVD records provide additional context. The vulnerability allows unauthenticated attackers who know a registered user's phone number to forge a token and take over that user's account, including administrator accounts. Defenders should verify affected product deployments, review official advisories, and plan vendor-supported updates or mitigations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-16030 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-16030

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-16030 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-16030

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.