External risk intelligence

Login with QR WordPress Plugin Authentication Bypass

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-86710

This vulnerability affects a WordPress plugin used for authentication. WordPress sites are frequently deployed as public-facing web applications, and authentication endpoints are inherently exposed to the internet to facilitate user login functionality.

Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability in a popular WordPress login plugin could allow unauthorized access to any user account, including administrator accounts, without any authentication. The issue arises from a failure to properly validate QR code credentials, potentially exposing sensitive systems to compromise. The main concern is confirming relevance and exposure to your organization.

  • Allows anyone to log in as any user.
  • Unauthenticated access to admin accounts is a major risk.
  • Confirm if this plugin is in use and assess exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted requests to a WordPress site using the affected plugin. Since the plugin does not properly validate the QR code used for login, the attacker can bypass authentication and gain access to any user account. This could potentially lead to full site compromise if an administrator account is accessed.

  • No authentication required.
  • Logging in with any QR code.
  • Full site takeover risk.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated attackers to log in as any user on a WordPress site using the affected plugin. This is possible because the plugin does not properly verify the QR code used for authentication, instead matching any stored user metadata.

  • User accounts could be compromised.
  • Attackers could log in without valid credentials.
  • Unauthorized access and control of the site.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in the Login with QR WordPress plugin, which allows unauthenticated administrative access, likely impacts any organization using this plugin on their WordPress sites. The first step is for the website or application owner to identify all instances of this plugin, assess their exposure, and confirm business criticality. Following this, the platform or infrastructure team, in coordination with security and potentially vendor management, should plan remediation based on the identified risk.

  • Website or application owners should own the issue.
  • Verify plugin presence and external reachability.
  • Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Login with QR WordPress plugin?

This is a WordPress plugin designed to simplify the login process by allowing users to scan a QR code to authenticate instead of typing a password. It integrates directly into the WordPress user metadata system to link specific codes with account identities.

What does CVE-2026-86710 mean for authentication security?

This vulnerability is classified as Improper Authentication (CWE-287). It means the plugin fails to check if a QR code was legitimately issued by the system. Instead, it accepts any code that matches existing user metadata, allowing an attacker to impersonate any user, including administrators.

How does an attacker trigger this vulnerability?

An attacker triggers this by sending a specially crafted request to the site that mimics the login process. The flaw is not triggered by scanning a valid code; rather, it is triggered by the plugin's logic error in validating any input against stored metadata. Normal, valid QR code use is not required for the exploit.

Is my site at risk according to Halo Surface Signal?

Halo Surface Signal notes that since this plugin manages authentication and is typically installed on public-facing WordPress sites, the login endpoint is inherently exposed to the internet. This makes it highly accessible to external attackers rather than restricted to internal networks.

What should I do if I use this plugin?

Begin by auditing your WordPress installations to confirm if this specific plugin is active. Once identified, evaluate the criticality of the affected site and prioritize removing or disabling the plugin until you can determine a safe path forward, such as reverting to standard authentication methods.

References