CyberRota Analysis
AI-GeneratedThe Firebase Authentication WordPress plugin prior to version 1.7.1 is vulnerable due to its failure to verify email addresses in authentication tokens, enabling unauthenticated attackers to gain access to any WordPress account, including those of administrators. This poses a significant security risk for WordPress sites utilizing this plugin, as it allows unauthorized access and potential exploitation of sensitive data. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this critical vulnerability.
Original NVD Description
The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a WordPress account and issuing a session, allowing unauthenticated attackers to log in as any user, including administrators.