What is CVE-2026-16030?
The MStore API WordPress plugin vulnerability fails to properly verify the cryptographic signature of tokens used for phone-based login. This allows unauthenticated attackers who know a registered user's phone number to forge tokens and take over that user's account, including admin accounts. Versions prior to 4.21.0 are affected and should be updated immediately.
Azərbaycanca: MStore API WordPress plaginindəki zəiflik telefon əsaslı giriş üçün istifadə olunan tokenin kriptoqrafik imzasını düzgün yoxlamır. Bu, qeydiyyatlı istifadəçinin telefon nömrəsini bilən autentifikasiya olunmamış hücumçulara tokeni saxtalaşdıraraq həmin istifadəçinin hesabını, o cümlədən admin hesablarını ələ keçirməyə imkan verir. Plaginin 4.21.0 versiyasından əvvəlki versiyaları təsirlənir və dərhal yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which versions of MStore API are affected by CVE-2026-16030?
All versions of the MStore API plugin prior to 4.21.0 are affected by this vulnerability.
How can an unauthenticated attacker take over an admin account via CVE-2026-16030?
If the attacker knows a registered admin user's phone number, they can forge the phone-based login token because the cryptographic signature is not properly verified, thereby taking over the admin account.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.