CVSS
8.1
CVSS v3.1
EPSS
0.2%
Exploit Prediction Score
Published
August 7, 2026
Exploitability
EPSS probability 0.2%
The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a token and take over that user's account, including administrator accounts.
No package data available.
Publisher and database URLs for this record (shown for attribution; reading stays in Bugflare).