Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

피드문의개인정보© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
CVE-2026-13447 — Proof-of-concept exploit for CVE-2026-13447, a critical authentication bypass in the WordPress MStore API plugin via forged Firebase JWT tokens, with a local lab reproduction. | Kitploit
도구/GitHubGitHub/abraxas/cve-2026-13447
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityCryptographyPenetration TestingAuthenticationLabs & Practice
GitHubabraxas/cve-2026-13447

CVE-2026-13447

Proof-of-concept exploit for CVE-2026-13447, a critical authentication bypass in the WordPress MStore API plugin via forged Firebase JWT tokens, with a local lab reproduction.

249일 전아직 검토되지 않음
저장소 보기

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
요청한 언어로 콘텐츠를 사용할 수 없습니다. 영어 버전을 표시합니다.

Abraxas Labs - CVE-2026-13447

abraxaslabs.tech  ·  github.com/abraxas  ·  @abraxas_null  ·  [email protected]  ·  CVE-2026-13447

CVE-2026-13447

MStore API 4.18.4 - inspireui

I am @abraxas_null. Loopback lab. The client is CVE-2026-13447-Abraxas-Labs.py.

The kid is not a signature. FirebasePhoneAuthHelper::verify_id_token checks alg == RS256, that kid is in Google's x509 list, that aud/iss match the uploaded Firebase project_id. Then it returns phone_number. It never calls openssl_verify. HTTP is POST /wp-json/api/flutter_user/firebase_sms_v2 with JSON id_token. NVD lists through 4.20.0. No 4.20.0 zip in the lab; 4.18.4 is the tree that ran. Patched in 4.21.1.

CVECVE-2026-13447 · CVE.org
CWECWE-287
CVSSCritical: 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ProductWordPress - MStore API
Affectedall versions through 4.20.0 (lab 4.18.4; no 4.20.0 zip)
Patched4.21.1 and later
Authnone
LicenseGNU Affero GPL v3.0
Lab127.0.0.1 only

What an attacker can do

Mint an RS256 JWT with a live Google kid, matching aud/iss, and a phone_number bound to an existing user. POST it. You get wp_user_id, cookie, displayname. That is admin if that phone is on admin. I am not printing the token.


How I found it

Wordfence named the missing openssl_verify. I read the helper, then the REST route, then bound a lab phone to admin.

GET Google's x509. Pick a kid. Build RS256. POST {id_token}. Witness POCWitness13447 as displayname, plus a cookie.

Wrong turns: action=verify_id_token (theme or REST 404); GET; alg not RS256; random kid; aud/iss not matching project_id (poc13447 in the lab file); no user with that registered_phone_number (User does not exist); Firebase private key file is not found (missing config, not a signature).


The lab

Port 8088. MStore API 4.18.4. Uploaded Firebase JSON project_id=poc13447. Admin phone meta bound.

  • lab/Dockerfile
  • lab/docker-compose.override.yml
  • lab/docker-compose.yml

Target only 127.0.0.1:8088 (or the loopback you bound).

cd lab
docker compose up --force-recreate
python3 ../CVE-2026-13447-Abraxas-Labs.py

Witness: Small JSON with wp_user_id, cookie, displayname POCWitness13447. id_token is invalid / homepage is not it.

Ways to lose without learning anything:

  • GET / wrong path / theme HTML
  • random kid / alg not RS256
  • User does not exist
  • reverse shell

The fix

Update MStore API to 4.21.1 or newer. Re-run CVE-2026-13447-Abraxas-Labs.py against the patched build: the forged JWT must not log anyone in.


References

  • CVE-2026-13447 · NVD

  • CVE-2026-13447 · CVE.org

  • plugins.trac.wordpress.org/browser/mstore-api/tags/4.18.4/controllers/flutter-user.php#L829

  • plugins.trac.wordpress.org/browser/mstore-api/tags/4.18.4/controllers/flutter-user.php#L940

  • plugins.trac.wordpress.org/browser/mstore-api/tags/4.18.4/controllers/helpers/firebase-phone-auth-helper.php#L5

  • plugins.trac.wordpress.org/browser/mstore-api/trunk/controllers/flutter-user.php#L829

  • plugins.trac.wordpress.org/browser/mstore-api/trunk/controllers/flutter-user.php#L940

  • plugins.trac.wordpress.org/browser/mstore-api/trunk/controllers/helpers/firebase-phone-auth-helper.php#L5

  • www.wordfence.com/threat-intel/vulnerabilities/id/4a1127af-74f6-4748-9aee-5a8c6c2766a4?source=cve

  • github.com/advisories/GHSA-6wfp-pwm3-667v

  • nvd.nist.gov/vuln/detail/CVE-2026-13447

  • Plugin directory: mstore-api

  • Trac browser: plugins.trac.wordpress.org/mstore-api

  • SVN tags: plugins.svn.wordpress.org/mstore-api

  • Abraxas Labs: abraxaslabs.tech · github.com/abraxas · @abraxas_null


License

GNU Affero GPL v3.0. See LICENSE.


The client talks to loopback. Using it against systems you do not own is not authorized by Abraxas Labs. No warranty.

abraxaslabs.tech · github.com/abraxas · @abraxas_null

도구 다운로드