Privilege Escalation in Firebase Support & Chat Management Plugin for WordPress
CVE-2026-8787
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 27 May 2026
What is CVE-2026-8787?
The Firebase Support & Chat Management plugin for WordPress has a critical flaw related to privilege escalation. This vulnerability allows authenticated attackers with Subscriber-level access and above to exploit the firebase_auth() function. The function indiscriminately authenticates requests using the email supplied in the user_email POST parameter, completely neglecting to verify ownership of that email. Consequently, this could enable attackers to log in as any existing user, including those with administrative privileges, by simply submitting the targeted user's email address to the acb_firebase_auth AJAX action. This flaw potentially leads to complete account takeover, compromising sensitive user information and system integrity.
Affected Version(s)
Firebase Support & Chat Management <= 3.1.1