PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-86710 Login with QR CVE debrief

The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in is one it issued, matching any stored user metadata value instead. This allows unauthenticated attackers to log in as any user, including administrators, potentially leading to unauthorized access and lateral movement within WordPress installations. Defenders should assess exposure and prioritize remediation efforts to restrict access to the plugin until a patched version is available, focusing on verifying the plugin version and monitoring for exploitation attempts.

Vendor
Login with QR
Product
Login with QR
CVSS
CRITICAL 9.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-17
Original CVE updated
2026-09-18
Advisory published
2026-09-17
Advisory updated
2026-09-18

Who should care

Defenders responsible for WordPress installations with the Login with QR plugin version 1.0.0 or earlier should assess exposure and prioritize remediation efforts. This includes IT security teams, system administrators, and anyone responsible for maintaining WordPress sites. These individuals should verify the plugin version, monitor for exploitation attempts, and restrict access to the plugin until a patched version is available.

Why it matters

CVE-2026-86710 allows unauthenticated attackers to log in as any user, including administrators, on WordPress installations with the Login with QR plugin version 1.0.0 or earlier. Defenders should prioritize verifying exposure and restricting access to the plugin until a patched version is available.

  • Unauthenticated attackers can log in as any user, including administrators
  • Potential for lateral movement and exploitation of additional vulnerabilities

Technical summary

The Login with QR WordPress plugin through 1.0.0 is vulnerable due to its lack of verification for the code used to log a user in. Instead of verifying the code, it matches any stored user metadata value. This oversight allows unauthenticated attackers to log in as any user, including administrators, by exploiting the plugin's authentication mechanism. The technical impact is significant, as it enables attackers to bypass authentication and potentially access sensitive information or take control of the WordPress installation.

Defensive priority

Defenders should prioritize verifying exposure of the Login with QR WordPress plugin version 1.0.0 or earlier and restrict access to the plugin until a patched version is available.

Recommended defensive actions

  • Verify exposure of the Login with QR WordPress plugin version 1.0.0 or earlier in your environment.
  • Restrict access to the plugin until a patched version is available.
  • Monitor for potential exploitation attempts and review system logs.
  • Implement compensating controls for exposed systems, such as additional authentication mechanisms.
  • Conduct an asset inventory to identify all instances of the plugin.
  • Plan for vendor-supported updates or mitigations through normal change control.
  • Track exceptions and retest remediated assets to ensure the vulnerability is fully addressed.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, but additional information from the vendor and other sources is limited. Defenders should verify the plugin version and check for any available patches or updates. The vulnerability's impact is critical, allowing unauthenticated attackers to gain administrative access. Evidence from the CVE Program and NVD suggests a high severity level, but further investigation by defenders is necessary to understand the full scope of the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-86710 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-86710

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-86710 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86710

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.