top of page
perceptive_background_267k.jpg

The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check always passes, and it discloses the generate…

Published:

26 July 2026 at 22:00:00

Alert date:

27 July 2026 at 21:04:07

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access, Zero-Day Vulnerabilities

The 微信二维码登陆 (WeChat QR Login) WordPress plugin through version 1.3 contains a critical authentication bypass vulnerability. The plugin fails to properly validate WeChat webhook requests because its signature verification check always returns a passing result. Additionally, the plugin discloses the generated login code in the webhook response. An unauthenticated attacker can exploit this by forging a webhook login event for any existing username, reading the login code from the response, and then redeeming it via an unauthenticated AJAX action. This effectively allows full account takeover of any user, including administrators, without requiring a password. No authentication or special privileges are needed to exploit this flaw.

Technical details

Mitigation steps:

Affected products:

微信二维码登陆 WordPress plugin 1.3
WordPress

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page