CRITICAL 9.8 CVE-2026-86710 Published 17 Sept 2026

WordPress Login with QR Plugin Unauthenticated Login Vulnerability

Worried this affects your website?

The Login with QR WordPress plugin, up to version 1.0.0, has a critical security flaw. It does not validate the QR code used for login, allowing attackers to log in as any user, including administrators, by matching any stored user metadata value.

This vulnerability affects all versions of the Login with QR plugin up to and including 1.0.0.

Reference: CVE-2026-86710 on NVD

← Back to Security News