CVE-2026-84734
Mindstien Quick Login <= 1.0 - Unauthenticated Administrator Account Takeover via 'mql_pass' Parameter
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Mindstien Quick Login WordPress plugin through 1.0 does not correctly validate a value supplied in the request against the visitor's own session before authenticating them, allowing unauthenticated attackers to obtain a session as the administrator account the Mindstien Quick Login WordPress plugin through 1.0 is configured with.
| Vendor | unknown |
| Product | mindstien quick login |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown mindstien quick login
Be the first to know when new unknown vulnerabilities affecting unknown mindstien quick login are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Mindstien Quick Login
0 โค 1.0
References
Credits
Naoki Kawahigashi WPScan