CyberRota Analysis
AI-GeneratedThe Login with QR WordPress plugin prior to version 1.0.0 is vulnerable due to a lack of verification for the login codes it issues, allowing unauthenticated attackers to bypass authentication and gain access to any user account, including those of administrators. This vulnerability poses a significant risk to WordPress sites utilizing the plugin, as it can lead to unauthorized access and potential compromise of sensitive data. WordPress site administrators using this plugin should prioritize immediate updates to mitigate this security threat.
Original NVD Description
The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators.