Improper Validation in WeChat Login Plugin for WordPress
CVE-2026-13597

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 July 2026

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2026-13597?

The 微信二维码登陆 plugin for WordPress versions up to 1.3 contains a security flaw that permits unauthorized access through weak validation of webhook requests. The plugin's signature verification fails, allowing an attacker to simulate a login event for any existing user by intercepting the webhook response, which exposes the login code. This vulnerability enables an unauthenticated actor to exploit the system, gaining access to user accounts, including that of an administrator, without any password requirement.

Affected Version(s)

微信二维码登陆 0 <= 1.3

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

João Ramos Maciel
WPScan
.