CVE-2026-76793
N/A
N/A
Summary
The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a WordPress account and issuing a session, allowing unauthenticated attackers to log in as any user, including administrators.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Firebase Authentication | 0 < 1.7.1 | affected |
Weaknesses
- CWE-287 Improper Authentication
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.