VYPR

Firebase OTP Authentication

by WordPress

CVEs (2)

  • CVE-2024-54294CriDec 13, 2024
    risk 0.64cvss 9.8epss 0.01

    Authentication Bypass Using an Alternate Path or Channel vulnerability in Appgenix Infotech Firebase OTP Authentication authentication-via-otp-using-firebase allows Authentication Bypass.This issue affects Firebase OTP Authentication: from n/a through <= 1.0.1.

  • CVE-2026-76793HigAug 22, 2026
    risk 0.53cvss 8.1epss 0.00

    The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matching it to a WordPress account and issuing a session, allowing unauthenticated attackers to log in as any user, including…