Impact
The Login with QR WordPress plugin, version 1.0.0 or earlier, fails to verify the 'autologin_code' parameter it receives during the QR-based login process. Instead of ensuring the code matches one it generated, the plugin accepts any code that matches a value stored in a user’s metadata. This flaw lets an unauthenticated attacker supply arbitrary codes and log in as any user, including administrators, potentially allowing full control over the WordPress site.
Affected Systems
WordPress sites that have the Login with QR plugin installed at any version up to and including 1.0.0 are affected. The vulnerability targets only the plugin’s QR authentication endpoint and does not directly impact other components of WordPress or unrelated plugins.
Risk and Exploitability
The assigned CVSS score of 9.8 indicates a critical severity. The EPSS score of less than 1% suggests that the likelihood of exploitation is currently low, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers can exploit the flaw remotely by sending a web request to the plugin’s login endpoint with a crafted 'autologin_code' value, so the likely attack vector is remote over the network. No authentication is required to initiate the exploit.
OpenCVE Enrichment