CVE-2026-84734 PUBLISHED

Mindstien Quick Login <= 1.0 - Unauthenticated Administrator Account Takeover via 'mql_pass' Parameter

Assigner: WPScan
Reserved: 02.09.2026 Published: 11.10.2026 Updated: 11.10.2026

The Mindstien Quick Login WordPress plugin through 1.0 does not correctly validate a value supplied in the request against the visitor's own session before authenticating them, allowing unauthenticated attackers to obtain a session as the administrator account the Mindstien Quick Login WordPress plugin through 1.0 is configured with.

Product Status

Vendor Unknown
Product Mindstien Quick Login
Versions Default: unknown
  • affected from 0 to 1.0 (incl.)

Credits

  • Naoki Kawahigashi finder
  • WPScan coordinator

References

Problem Types

  • CWE-287 Improper Authentication CWE