Forums

No More Passwords
Security issue (4 posts)

  1. Julio Potier (Juliobox)
    Member
    Posted 4 months ago #

    Hello, i’m Julio from BoiteAWeb.fr
    I’m Web Security Consultant.
    I discover a big vulnerability in your plugin.
    I can login with any account, of course like you said “with no password” ;)
    Contact me to get the exploit code:
    gtalk/email: [ email redacted ]
    skype: [ redacted ]

    See you

    http://wordpress.org/extend/plugins/wp-qr-code-login/

  2. bamajr
    Member
    Posted 3 months ago #

    I'm curious if anyone has been able to duplicate your claim @juliobox?

    If so, I'm wondering if it has been addressed yet in this plugin?

  3. Julio Potier (Juliobox)
    Member
    Posted 3 months ago #

    Hello

    the 0.5 actually correct the discovered vulnerabilities, but, a new XSS comes out in the same time.

    The author did not yet respond to my last emails.

    Stay tuned !

  4. jackreichert
    Member
    Posted 3 months ago #

    Version 1.1, I believe, has proper sanitization now so no more xss nor sql injection holes....

Reply

You must log in to post.

About this Plugin

About this Topic