CyberRota Analysis
AI-GeneratedThe MStore API WordPress plugin prior to version 4.21.0 is vulnerable due to improper verification of cryptographic signatures for authentication tokens used in phone-based logins. This flaw allows unauthenticated attackers with knowledge of a registered user's phone number to forge authentication tokens, potentially leading to account takeover, including access to administrator accounts. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a token and take over that user's account, including administrator accounts.