Session Management Flaw in Mindstien Quick Login Plugin for WordPress
CVE-2026-84734
Currently unrated
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 11 October 2026
Badges
👾 Exploit Exists🟡 Public PoC
What is CVE-2026-84734?
The Mindstien Quick Login plugin for WordPress, up to version 1.0, possesses a security oversight where it fails to correctly validate request input against the user’s session during the authentication process. This flaw allows an unauthorized attacker to exploit the system and obtain a session as the administrator, thereby compromising the security of the WordPress installation.
Affected Version(s)
Mindstien Quick Login 0 <= 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.