AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-16030

HIGH · CVSS 8.1 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The MStore API WordPress plugin prior to version 4.21.0 is vulnerable due to improper verification of cryptographic signatures for authentication tokens used in phone-based logins. This flaw allows unauthenticated attackers with knowledge of a registered user's phone number to forge authentication tokens, potentially leading to account takeover, including access to administrator accounts. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-16030
Severity
HIGH
CVSS
8.1
EPSS
0.23%
WordPress

Original NVD Description

The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a token and take over that user's account, including administrator accounts.