


Perceptive Security
SOC/SIEM Consultancy

The 微信二维码登陆 WordPress plugin through 1.3 does not properly validate WeChat webhook requests, as its signature check always passes, and it discloses the generate…
Published:
26 July 2026 at 22:00:00
Alert date:
27 July 2026 at 21:04:07
Source:
nvd.nist.gov
Web Technologies, Identity & Access, Zero-Day Vulnerabilities
The 微信二维码登陆 (WeChat QR Login) WordPress plugin through version 1.3 contains a critical authentication bypass vulnerability. The plugin fails to properly validate WeChat webhook requests because its signature verification check always returns a passing result. Additionally, the plugin discloses the generated login code in the webhook response. An unauthenticated attacker can exploit this by forging a webhook login event for any existing username, reading the login code from the response, and then redeeming it via an unauthenticated AJAX action. This effectively allows full account takeover of any user, including administrators, without requiring a password. No authentication or special privileges are needed to exploit this flaw.
Technical details
Mitigation steps:
Affected products:
微信二维码登陆 WordPress plugin 1.3
WordPress
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-13597
https://wpscan.com/vulnerability/5e856219-ece5-4d79-8375-fc0cbdc37d6c/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
