Description
The Mindstien Quick Login WordPress plugin through 1.0 does not correctly validate a value supplied in the request against the visitor's own session before authenticating them, allowing unauthenticated attackers to obtain a session as the administrator account the Mindstien Quick Login WordPress plugin through 1.0 is configured with.
Published: 2026-10-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated Administrator Account Takeover
Action: Immediate Patch
AI Analysis

Impact

The Vulnerability allows an attacker to bypass the Normal authentication flow by supplying a specially crafted request parameter, thereby gaining a session token that belongs to the administrator account through which the plugin was configured. The lack of proper session validation permits an outside actor to assume full administrative privileges within the WordPress site. This creates a high‑impact threat of full control over content, configuration and potential data exposure.

Affected Systems

Any WordPress site running Mindstien Quick Login plugin version 1.0 or earlier. The plugin is published by an unknown vendor and is accessible through the standard WordPress plugin repository. No specific WordPress core version is required for exploitation. The vulnerability applies to all installations where the plugin is active and has an administrator account configured.

Risk and Exploitability

The exploit requires only an unauthenticated HTTP request to the plugin’s entry point with the 'mql_pass' parameter. No special privileges or user interaction are needed. An attacker can construct a request and receive an authenticated session cookie if the plugin accepts the injected value. The CVSS score is not available, but the EPSS score is missing and the vulnerability is not listed as a Known Exploited Vulnerability by CISA, implying no confirmed public exploitation yet. Nevertheless, the impact of the flaw and the relative simplicity of the attack vector make it a high‑risk issue that should be addressed promptly.

Generated by OpenCVE AI on October 11, 2026 at 08:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Download and install the latest version of Mindstien Quick Login (any release newer than 1.0); if no newer release is available, uninstall the plugin entirely.
  • If upgrade or removal is impractical, immediately configure a plugin hardening setting to reject any unauthenticated password submissions, or manually edit the plugin files to enforce a proper session check for the 'mql_pass' parameter.
  • Block access to the plugin’s specific endpoint using a web‑application firewall rule or server‑side access control that permits only authenticated administrative sessions.

Generated by OpenCVE AI on October 11, 2026 at 08:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 11 Oct 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287

Sun, 11 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Mindstien Quick Login WordPress plugin through 1.0 does not correctly validate a value supplied in the request against the visitor's own session before authenticating them, allowing unauthenticated attackers to obtain a session as the administrator account the Mindstien Quick Login WordPress plugin through 1.0 is configured with.
Title Mindstien Quick Login <= 1.0 - Unauthenticated Administrator Account Takeover via 'mql_pass' Parameter
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-11T11:32:44.662Z

Reserved: 2026-09-02T08:27:13.495Z

Link: CVE-2026-84734

cve-icon Vulnrichment

Updated: 2026-10-11T11:23:59.780Z

cve-icon NVD

Status : Received

Published: 2026-10-11T07:17:25.687

Modified: 2026-10-11T12:17:23.780

Link: CVE-2026-84734

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T08:15:17Z

Weaknesses