CVE-2026-86710 UNKNOWN

CVE-2026-86710

Published: 2026-09-17

Description

The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…