CRITICAL
inspireui
CVE published 2026-09-05
CVE-2026-13447
The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0. This vulnerability allows unauthenticated attackers to forge a Firebase Phone Auth JWT signed with a self-generated RSA key pair and impersonate any phone number, potentially resulting in unauthorized access to existing WordPress accounts or creation of new arbitrary accounts.