Description
The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators.
Published: 2026-09-17
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Authentication bypass with potential privilege escalation
Action: Immediate Mitigation
AI Analysis

Impact

The Login with QR WordPress plugin, version 1.0.0 or earlier, fails to verify the 'autologin_code' parameter it receives during the QR-based login process. Instead of ensuring the code matches one it generated, the plugin accepts any code that matches a value stored in a user’s metadata. This flaw lets an unauthenticated attacker supply arbitrary codes and log in as any user, including administrators, potentially allowing full control over the WordPress site.

Affected Systems

WordPress sites that have the Login with QR plugin installed at any version up to and including 1.0.0 are affected. The vulnerability targets only the plugin’s QR authentication endpoint and does not directly impact other components of WordPress or unrelated plugins.

Risk and Exploitability

The assigned CVSS score of 9.8 indicates a critical severity. The EPSS score of less than 1% suggests that the likelihood of exploitation is currently low, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers can exploit the flaw remotely by sending a web request to the plugin’s login endpoint with a crafted 'autologin_code' value, so the likely attack vector is remote over the network. No authentication is required to initiate the exploit.

Generated by OpenCVE AI on September 18, 2026 at 01:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Remove or disable the Login with QR plugin from the WordPress installation.
  • If an updated version of the plugin that addresses the vulnerability is available, update the plugin immediately.
  • Apply restrictions to WordPress administrative pages and endpoints and consider using additional security plugins to detect and block suspicious login attempts.

Generated by OpenCVE AI on September 18, 2026 at 01:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators.
Title Login with QR <= 1.0.0 - Unauthenticated Authentication Bypass via 'autologin_code' Parameter
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-17T12:29:28.971Z

Reserved: 2026-09-08T10:58:07.518Z

Link: CVE-2026-86710

cve-icon Vulnrichment

Updated: 2026-09-17T12:12:34.163Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T06:16:51.437

Modified: 2026-09-18T19:08:32.830

Link: CVE-2026-86710

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T02:00:16Z

Weaknesses