WordPress Social Login, Passkeys, Magic Link & Email OTP Plugin Passwordless Login Vulnerability Allowing Unauthenticated Account Takeover

Vulnerability

A vulnerability exists in the Social Login, Passkeys, Magic Link & Email OTP WordPress plugin in versions prior to 1.4.1. The plugin fails to implement rate limiting or effective attempt lockout on its passwordless email one-time-password (OTP) verification process. Additionally, the short numeric codes are stored in plaintext. This allows an unauthenticated attacker with knowledge of a registered email address to brute-force the OTP code and gain access to the corresponding user account, including those of administrators, potentially leading to a complete site takeover.

Impact

Exploitation of this vulnerability allows for unauthorized access to user accounts, including administrative accounts, facilitating a full site takeover.

Remediation

Users are advised to update the WordPress Social Login, Passkeys, Magic Link & Email OTP plugin to version 1.4.1 or later.

Added: Jul 20, 2026, 7:27 AM
Updated: Jul 20, 2026, 7:27 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.6
remediation
0.0
relevance
10.0
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.