CVE-2026-13597

微信二维码登陆 (WeChat QR Login) · 微信二维码登陆 (WeChat QR Login)

The 微信二维码登陆 WordPress plugin fails to validate WeChat webhook signatures, allowing unauthenticated attackers to forge login events and impersonate any user, including administrators.

Executive summary

A critical authentication bypass in the 微信二维码登陆 plugin allows unauthenticated attackers to hijack user accounts and gain administrative privileges.

Vulnerability

The plugin incorrectly validates WeChat webhook requests and exposes login codes. An unauthenticated attacker can exploit this to forge login events and authenticate as any user on the system without a password.

Business impact

This vulnerability enables full account takeover, including administrative accounts, which can lead to total site compromise. Given the CVSS score of 9.1, this flaw presents an extreme threat to data confidentiality and integrity.

Remediation

Immediate Action: Update the 微信二维码登陆 plugin to the latest available version if a patch is provided, or deactivate the plugin immediately until a fix is verified.

Proactive Monitoring: Review user login logs for suspicious activity or accounts being accessed from unexpected locations or via the WeChat login method.

Compensating Controls: Disable the WeChat login functionality within the plugin settings to mitigate the risk until the vendor provides a permanent patch.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

This is a critical security failure that permits unauthorized account access. Because the plugin does not properly secure the authentication process, it is recommended to deactivate the plugin immediately if an update is not readily available to prevent potential account takeovers.