8.8
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
The Firebase Support & Chat Management plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.1.1. This is due to the `firebase_auth()` function authenticating the request as the WordPress user whose email is supplied in the `user_email` POST parameter without verifying ownership of that email (no Firebase ID token signature/issuer/audience verification). This makes it possible for authenticated attackers, with Subscriber-level access and above, to log in as an arbitrary existing user — including an Administrator — by submitting that user's email address to the `acb_firebase_auth` AJAX action, resulting in full account takeover.
AI Analysis
Privilege escalation vulnerability due to missing authorization in the Firebase Support & Chat Management plugin for WordPress, allowing authenticated attackers to log in as an arbitrary existing user, including an Administrator.
Basic Information
ID
CVE-2026-8787
Source
Wordfence
Published
May 27, 2026 at 05:31
Affected Product
Vendor
devsabbirahmed
Product
Firebase Support & Chat Management
Version
<= 3.1.1
Affected Versions
devsabbirahmed Firebase Support & Chat Management <= 3.1.1
CWE Classification
AI Assessment
AI Score
8.8 / 10
AI Severity
High
Vendor
devsabbirahmed
Product
Firebase Support & Chat Management
Version
<= 3.1.1
References
- www.wordfence.com /threat-intel/vulnerabilities/id/90783d75-a255-4133-ac7b-32e0a70c8c69
- plugins.trac.wordpress.org /browser/admin-chat-box/tags/3.1.1/inc/ACB_AjaxHandler.php
- plugins.trac.wordpress.org /browser/admin-chat-box/trunk/inc/ACB_AjaxHandler.php
- plugins.trac.wordpress.org /browser/admin-chat-box/tags/3.1.1/inc/ACB_AjaxHandler.php
- plugins.trac.wordpress.org /browser/admin-chat-box/trunk/inc/ACB_AjaxHandler.php