Impact
The Vulnerability allows an attacker to bypass the Normal authentication flow by supplying a specially crafted request parameter, thereby gaining a session token that belongs to the administrator account through which the plugin was configured. The lack of proper session validation permits an outside actor to assume full administrative privileges within the WordPress site. This creates a high‑impact threat of full control over content, configuration and potential data exposure.
Affected Systems
Any WordPress site running Mindstien Quick Login plugin version 1.0 or earlier. The plugin is published by an unknown vendor and is accessible through the standard WordPress plugin repository. No specific WordPress core version is required for exploitation. The vulnerability applies to all installations where the plugin is active and has an administrator account configured.
Risk and Exploitability
The exploit requires only an unauthenticated HTTP request to the plugin’s entry point with the 'mql_pass' parameter. No special privileges or user interaction are needed. An attacker can construct a request and receive an authenticated session cookie if the plugin accepts the injected value. The CVSS score is not available, but the EPSS score is missing and the vulnerability is not listed as a Known Exploited Vulnerability by CISA, implying no confirmed public exploitation yet. Nevertheless, the impact of the flaw and the relative simplicity of the attack vector make it a high‑risk issue that should be addressed promptly.
OpenCVE Enrichment