
CVE-2026-76793 The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a WordPre… https://www.cve.org/CVERecord?id=CVE-2026-76793
Post summary
The Firebase Authentication WordPress plugin version 1.7.0 and earlier contain a vulnerability that fails to verify the email address in authentication tokens, potentially allowing token misuse, though no proof‑of‑concept, exploit, or active exploitation has been reported.

