CVE-2026-86710 PUBLISHED

Login with QR <= 1.0.0 - Unauthenticated Authentication Bypass via 'autologin_code' Parameter

Assigner: WPScan
Reserved: 08.09.2026 Published: 17.09.2026 Updated: 17.09.2026

The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators.

Product Status

Vendor Unknown
Product Login with QR
Versions Default: unknown
  • affected from 0 to 1.0.0 (incl.)

Credits

  • Naoki Kawahigashi finder
  • WPScan coordinator

References

Problem Types

  • CWE-287 Improper Authentication CWE