SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-76793

HIGH · CVSS 8.1 EPSS 0.35%

Source: NVD + CISA KEV + EPSS · Published 2026-08-22 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Firebase Authentication WordPress plugin prior to version 1.7.1 is vulnerable due to its failure to verify email addresses in authentication tokens, enabling unauthenticated attackers to gain access to any WordPress account, including those of administrators. This poses a significant security risk for WordPress sites utilizing this plugin, as it allows unauthorized access and potential exploitation of sensitive data. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this critical vulnerability.

CVE
CVE-2026-76793
Severity
HIGH
CVSS
8.1
EPSS
0.35%
WordPress

Original NVD Description

The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a WordPress account and issuing a session, allowing unauthenticated attackers to log in as any user, including administrators.