What is CVE-2026-13597?
The "微信二维码登陆" WordPress plugin up to version 1.3 fails to properly validate WeChat webhook requests because the signature check always passes, and it exposes the generated login code in the webhook response. This allows an unauthenticated attacker to forge a login event for any existing username and read the login code. Site owners should immediately disable or remove the plugin until a patched version is released.
Azərbaycanca: Bu CVE 1.3-ə qədər "微信二维码登陆" WordPress plaginində WeChat webhook sorğularının düzgün yoxlanılmaması ilə bağlıdır. İmza yoxlanışı həmişə keçdiyi üçün autentifikasiya olunmamış hücumçu istənilən istifadəçi adı üçün saxta giriş hadisəsi yaradıb yaradılan giriş kodunu oxuya bilər. Sayt sahibləri plaqini dərhal söndürməli və ya rəsmi yamaq çıxana qədər istifadə etməməlidir.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which versions of the "微信二维码登陆" WordPress plugin are affected by CVE-2026-13597?
All versions up to 1.3 are affected.
What should site owners do to protect against this vulnerability until a patched version is released?
They should immediately disable or remove the plugin.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.