logo

CVE-2026-13597: WeChat QR Login WordPress Plugin Authentication Bypass

ID: 2aa850b7-a978-5902-b77d-d057217c6f07

STIX ID: report--2aa850b7-a978-5902-b77d-d057217c6f07

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-07-27

Date Updated: 2026-07-28

...
...

A critical authentication bypass (CVE-2026-13597, CVSS 9.1) in the WeChat QR Login WordPress plugin (<= 1.3) lets unauthenticated attackers forge WeChat webhook requests because the signature check always returns true and the plugin discloses the generated login code in the webhook response; an attacker can therefore obtain a login code and achieve full account takeover (including administrators). No patch is available — the advisory recommends disabling or uninstalling the plugin immediately, reviewing for unauthorized access, forcing admin password resets, and blocking the webhook endpoint until a fix is provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.