Junglewise Threat Intelligence

CVE-2026-13597: WeChat QR Code Login WordPress plugin authentication bypass

CVE-2026-13597 · Severity: info · CVSS 9.8 · Published 2026-07-27

Vendors: Unknown.

Executive brief

A vulnerability in the WeChat QR Code Login plugin for WordPress allows unauthorized individuals to take over any user account, including administrators. The plugin, which enables users to log into websites using WeChat QR codes, fails to verify the authenticity of login requests. An attacker can exploit this to bypass the password requirement and gain full control over the website and its data.

Technical details

The '微信二维码登陆' (qrcode-login-for-weixin) plugin fails to properly validate WeChat webhook requests because its signature verification logic is flawed and always returns a successful result. Furthermore, the plugin's webhook response inadvertently discloses the generated login code. An unauthenticated remote attacker can forge a login event for a known username, intercept the login code from the response, and then redeem that code via an unauthenticated AJAX action. This results in a complete authentication bypass, allowing the attacker to gain access to any account without a password. As of the advisory date, no fix is available.

Affected products

  • Unknown 微信二维码登陆 (QRcode Login for WeChat) <= 1.3

Timeline

  • 2026-07-06: disclosed: Publicly published via WPScan
  • 2026-07-27: advisory: CVE published to NVD dataset

References