{"id":"CVE-2026-86710","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-86710","summary":"The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in is one it issued, matching any stored user metadata value instead, which allows…","details":"The Login with QR WordPress plugin through 1.0.0 does not verify that the code used to log a user in is one it issued, matching any stored user metadata value instead, which allows unauthenticated attackers to log in as any user, including administrators.","published":"2026-09-17T06:16:51.437","modified":"2026-09-17T06:16:51.437","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://wpscan.com/vulnerability/d37dab2e-b137-4ad7-ab07-9c36b42a6485/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-17T06:16:51.437"}}