OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-86710

CRITICAL · CVSS 9.8 EPSS 0.50%

Source: NVD + CISA KEV + EPSS · Published 2026-09-17 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

The Login with QR WordPress plugin prior to version 1.0.0 is vulnerable due to a lack of verification for the login codes it issues, allowing unauthenticated attackers to bypass authentication and gain access to any user account, including those of administrators. This vulnerability poses a significant risk to WordPress sites utilizing the plugin, as it can lead to unauthorized access and potential compromise of sensitive data. WordPress site administrators using this plugin should prioritize immediate updates to mitigate this security threat.

CVE
CVE-2026-86710
Severity
CRITICAL
CVSS
9.8
EPSS
0.50%
WordPress

Original NVD Description

The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators.