PT-2026-64840 · WordPress · 微信二维码登陆

CVE-2026-13597

·

Published

2026-07-27

·

Updated

2026-07-27

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions 微信二维码登陆 WordPress plugin versions prior to 1.4
Description Insufficient validation of WeChat webhook requests occurs because the signature check always passes. Additionally, the plugin discloses the generated login code within the webhook response. This allows an unauthenticated attacker to forge a login event for any existing username, retrieve the login code, and use an unauthenticated AJAX action to log in as that user, including administrators, without requiring a password.
Recommendations Update the plugin to a version newer than 1.3.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13597

Affected Products

微信二维码登陆