QRcode Login for WeChat <= 1.3 - Unauthenticated Privilege Escalation via Account Takeover

2026-07-06 00:00
João Ramos Maciel

Strategic Overview

Status
Unpatched
Affected Plugin微信二维码登陆
Affected Version<= 1.3
CVSS9.8Critical
CVECVE-2026-13597
View all 微信二维码登陆 vulnerabilities

Vulnerability Overview

The QRcode Login for WeChat plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.3. This makes it possible for unauthenticated attackers to authenticate as other users, including administrators.

Technical Analysis

REMEDIATION: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement. --- IDENTIFIER: CWE-287 (Improper Authentication) When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C