Token Authentication Bypass in MStore API WordPress Plugin
CVE-2026-16030
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 7 August 2026
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2026-16030?
The MStore API WordPress plugin prior to version 4.21.0 fails to properly validate the cryptographic signature of the token used for phone-based login. This flaw enables unauthorized attackers, who are aware of a registered user's phone number, to create a forged token, potentially allowing them to gain access to the user's account, including those with administrative privileges.
Affected Version(s)
MStore API 0 < 4.21.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.