← Back to CVE List
CVE-2026-86710Wordfence
Vulnerability Summary
The Login with QR plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.0. This makes it possible for unauthenticated attackers to bypass authentication and log in as any user, including administrators.
CVSS v3.1 Base Metrics — Score 9.8 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Login with QR * - 1.0.0
Not provided by Wordfence for this CVE.