abraxaslabs.tech · github.com/abraxas · @abraxas_null · CVE-2026-13447
WordPress — MStore API 4.18.4 — inspireui
WordPress 的 Mstore Api 插件在 4.20.0 及之前版本中存在通过 JWT 伪造实现的认证绕过漏洞。这是由于 FirebasePhoneAuthHelper::verify_id_token() 函数缺少加密签名验证,该函数会解码并验证 Firebase ID token 的声明(alg、kid、aud、iss),但从未调用 openssl_verify() 或任何等效方法来根据 Google 的实际公钥证书验证 JWT 签名。这使得未认证的攻击者能够使用自行生成的 RSA 密钥对伪造 Firebase Phone Auth JWT,并冒充任意电话号码,从而未经授权访问现有 WordPress 账户或创建新的任意账户。
| CVE | CVE-2026-13447 · CVE.org |
| CWE | CWE-287 |
| CVSS | 严重:9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 产品 | WordPress — MStore API |
| 受影响 | 所有版本 至 4.20.0(实验环境 4.18.4;无 4.20.0 zip) |
| 已修复 | 4.21.1 及更高版本 |
| 认证 | 无(见源码映射) |
| 许可证 | GNU Affero GPL v3.0 |
| 实验环境 | 仅 127.0.0.1 · 供应商/客户披露包,非扫描器 |
verify_id_token 是漏洞汇聚点。HTTP 请求为 POST firebase_sms_v2,携带 JSON id_token,而非名为 verify_id_token 的查询参数。
POST/wp-json/api/flutter_user/firebase_sms_v2GET Google x509 metadata, pick a kidBuild unsigned-verify JWT RS256 kid=that, aud=poc13447, iss=https://securetoken.google.com/poc13447, phone_number=+15551213447POST /wp-json/api/flutter_user/firebase_sms_v2 {id_token}verify_id_token skips openssl_verify, returns +15551213447firebase_sms_login_v2 get_users registered_phone_number=that phone -> user 1JSON cookie + displayname POCWitness13447POST JSON 正文包含 POCWitness13447(管理员 displayname)和 cookie。不含该字符串的通用 200 响应不算成功。
首先执行: 将 MStore API 更新至 4.21.1 或更新版本。
升级后验证
CVE-2026-13447-Abraxas-Labs.py:映射的见证不得出现。如果无法立即更新
仅针对 http://127.0.0.1:8088(或你绑定的回环地址)。不要将此脚本指向互联网。
python3 CVE-2026-13447-Abraxas-Labs.py
成功标志是响应正文中出现上述见证。通用的 200 HTML 不算成功。
用于复现的回环栈。除非此文件夹中的 Dockerfile 从源码构建,否则使用官方镜像。
cd lab
docker compose up --force-recreate
如果 YAML 挂载了本地目录(来自版本表的插件 zip / 源码标签),请将存在漏洞的产品目录树绑定到 Compose 旁边。除 127.0.0.1 外不要发布任何内容。
plugins.trac.wordpress.org/browser/mstore-api/tags/4.18.4/controllers/flutter-user.php#L829
plugins.trac.wordpress.org/browser/mstore-api/tags/4.18.4/controllers/flutter-user.php#L940
plugins.trac.wordpress.org/browser/mstore-api/trunk/controllers/flutter-user.php#L829
plugins.trac.wordpress.org/browser/mstore-api/trunk/controllers/flutter-user.php#L940
www.wordfence.com/threat-intel/vulnerabilities/id/4a1127af-74f6-4748-9aee-5a8c6c2766a4?source=cve
插件目录:mstore-api
Abraxas Labs:abraxaslabs.tech · github.com/abraxas · @abraxas_null
# CVE-2026-13447 (structured records)
- input: `https://nvd.nist.gov/vuln/detail/CVE-2026-13447`
- CWE: CWE-287
- published: 2026-09-05T06:17:09.403
## NVD description
The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_token() function, which decodes and validates Firebase ID token claims (alg, kid, aud, iss) but never calls openssl_verify() or any equivalent to validate the JWT signature against Google's actual public key certificates. This makes it possible for unauthenticated attackers to forge a Firebase Phone Auth JWT signed with a self-generated RSA key pair and impersonate any phone number, resulting in unauthorized access to existing WordPress accounts or creation of new arbitrary accounts.
## MITRE description
The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_token() function, which decodes and validates Firebase ID token claims (alg, kid, aud, iss) but never calls openssl_verify() or any equivalent to validate the JWT signature against Google's actual public key certificates. This makes it possible for unauthenticated attackers to forge a Firebase Phone Auth JWT signed with a self-generated RSA key pair and impersonate any phone number, resulting in unauthorized access to existing WordPress accounts or creation of new arbitrary accounts.
## Affected
- inspireui MStore API – Create Native Android & iOS Apps On The Cloud 0 affected
## References (JSON sources only)
- https://plugins.trac.wordpress.org/browser/mstore-api/tags/4.18.4/controllers/flutter-user.php#L829
- https://plugins.trac.wordpress.org/browser/mstore-api/tags/4.18.4/controllers/flutter-user.php#L940
- https://plugins.trac.wordpress.org/browser/mstore-api/tags/4.18.4/controllers/helpers/firebase-phone-auth-helper.php#L5
- https://plugins.trac.wordpress.org/browser/mstore-api/trunk/controllers/flutter-user.php#L829
- https://plugins.trac.wordpress.org/browser/mstore-api/trunk/controllers/flutter-user.php#L940
- https://plugins.trac.wordpress.org/browser/mstore-api/trunk/controllers/helpers/firebase-phone-auth-helper.php#L5
- https://www.wordfence.com/threat-intel/vulnerabilities/id/4a1127af-74f6-4748-9aee-5a8c6c2766a4?source=cve
- https://github.com/advisories/GHSA-6wfp-pwm3-667v
- https://nvd.nist.gov/vuln/detail/CVE-2026-13447
## GitHub advisory
The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in...
The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic signature verification in the FirebasePhoneAuthHelper::verify_id_token() function, which decodes and validates Firebase ID token claims (alg, kid, aud, iss) but never calls openssl_verify() or any equivalent to validate the JWT signature against Google's actual public key certificates. This makes it possible for unauthenticated attackers to forge a Firebase Phone Auth JWT signed with a self-generated RSA key pair and impersonate any phone number, resulting in unauthorized access to existing WordPress accounts or creation of new arbitrary accounts.
本披露包依据 GNU Affero General Public License v3.0 许可。见 LICENSE。
本包仅供供应商、站点所有者及授权实验室使用。该脚本仅与 127.0.0.1 通信。将其用于你并不拥有的系统未获 Abraxas Labs 授权。不提供任何担保。