PT-2026-64840 · WordPress · 微信二维码登陆
CVE-2026-13597
·
Published
2026-07-27
·
Updated
2026-07-27
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
微信二维码登陆 WordPress plugin versions prior to 1.4
Description
Insufficient validation of WeChat webhook requests occurs because the signature check always passes. Additionally, the plugin discloses the generated login code within the webhook response. This allows an unauthenticated attacker to forge a login event for any existing username, retrieve the login code, and use an unauthenticated AJAX action to log in as that user, including administrators, without requiring a password.
Recommendations
Update the plugin to a version newer than 1.3.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
微信二维码登陆