cvedb.io
CVE-2026-16030
HIGH · CVSS 8.1
EPSS exploitation probability: 0%
Published 2026-08-07T06:16:55.833 · Last modified 2026-08-07T18:17:09.153

Summary

The MStore API WordPress plugin before 4.21.0 does not correctly verify the cryptographic signature of the token used to authenticate its phone-based login, allowing unauthenticated attackers who know a registered user's phone number to forge a token and take over that user's account, including administrator accounts.

Does this affect you?

Add your gear to cvedb and we'll alert you only when a vendor you run ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.