[CVE-2026-76793] The Firebase Authentication WordPress plugin before 1.7.1 do

CVE-2026-76793 | CVSS: N/A

The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a WordPress account and issuing a session, allowing unauthenticated attackers to log in as any user, including administrators.

参考链接:
https://wpscan.com/vulnerability/0414ef2b-0d97-41c7-9146-f31ace8b66b2/

📌 数据来源: NVD 官方

⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。
滚动至顶部