VentraConnect Social Login, Passkeys, Magic Link & Email OTP
- < 1.4.1
A vulnerability exists in the Social Login, Passkeys, Magic Link & Email OTP WordPress plugin in versions prior to 1.4.1. The plugin fails to implement rate limiting or effective attempt lockout on its passwordless email one-time-password (OTP) verification process. Additionally, the short numeric codes are stored in plaintext. This allows an unauthenticated attacker with knowledge of a registered email address to brute-force the OTP code and gain access to the corresponding user account, including those of administrators, potentially leading to a complete site takeover.
Exploitation of this vulnerability allows for unauthorized access to user accounts, including administrative accounts, facilitating a full site takeover.
Users are advised to update the WordPress Social Login, Passkeys, Magic Link & Email OTP plugin to version 1.4.1 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.