Understanding and Defending Against CVE-2026-16030: MStore API WordPress Plugin Vulnerability
The MStore API WordPress plugin before version 4.21.0 is vulnerable to token forgery, allowing unauthenticated attackers to take over user accounts, including administrator accounts, by forging a token if they know a registered user's phone number. This vulnerability has a CVSS score of 8.1, indicating high severity. Understanding the root cause, attack surface, and exploitation mechanics is crucial for defenders to implement effective mitigations and detections.