Privilege Escalation in Firebase Support & Chat Management Plugin for WordPress
CVE-2026-8787

8.8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 May 2026

What is CVE-2026-8787?

The Firebase Support & Chat Management plugin for WordPress has a critical flaw related to privilege escalation. This vulnerability allows authenticated attackers with Subscriber-level access and above to exploit the firebase_auth() function. The function indiscriminately authenticates requests using the email supplied in the user_email POST parameter, completely neglecting to verify ownership of that email. Consequently, this could enable attackers to log in as any existing user, including those with administrative privileges, by simply submitting the targeted user's email address to the acb_firebase_auth AJAX action. This flaw potentially leads to complete account takeover, compromising sensitive user information and system integrity.

Affected Version(s)

Firebase Support & Chat Management <= 3.1.1

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Farrukh Ziyaev
.