CVE-2026-13447 is an unauthenticated authentication-bypass vulnerability in the MStore API plugin for WordPress through version 4.20.0. The FirebasePhoneAuthHelper::verify_id_token() function parses Firebase ID tokens and validates claims such as alg, kid, aud, and iss, but does not cryptographically verify the JWT signature against Google's public-key certificates. An attacker can therefore construct a token containing acceptable claims and sign it with an attacker-controlled RSA key pair.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This seven-file repository is an operational, local-lab-focused proof of concept for CVE-2026-13447, an unauthenticated authentication bypass in the inspireui MStore API WordPress plugin. Its primary Python entry point, `CVE-2026-13447-Abraxas-Labs.py`, fetches a current Firebase/Google certificate key ID, creates a Firebase-style RS256 JWT with an arbitrary signature, and POSTs it to MStore API's Firebase SMS login REST endpoint. The exploit relies on the affected `verify_id_token()` logic checking token metadata and claims but not cryptographically validating the signature. Successful exploitation impersonates the fixed phone number and returns the mapped user's login cookie/display name; the included witness is `POCWitness13447`. The exploit is deliberately hardcoded for `127.0.0.1:8088` and does not include reverse-shell or RCE behavior. Repository support files consist of an AGPL-3.0 license, README/advisory, and Docker Compose files that define a loopback-only WordPress 6.4/PHP 8.2 Apache lab with MySQL 8.0 and a mounted MStore API plugin directory. Documentation identifies versions through 4.20.0 as affected and 4.21.1+ as patched, while the bundled lab is pinned to plugin version 4.18.4.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An authentication-bypass vulnerability in the Mstore Api WordPress plugin through version 4.20.0. The Firebase ID-token verification routine validates claims but does not verify the JWT cryptographic signature, enabling attackers to sign forged tokens with self-generated RSA keys, impersonate phone numbers, and access existing accounts or create arbitrary accounts.
A critical unauthenticated authentication-bypass vulnerability in the WordPress MStore API plugin through version 4.20.0. The Firebase Phone Auth ID-token verification routine validates token claims but does not cryptographically verify the JWT signature. An attacker can sign a forged Firebase Phone Auth JWT with a self-generated RSA key, impersonate a phone number, and gain access to an existing WordPress account or create arbitrary accounts.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.