CVE-2026-13142 PUBLISHED

Passwordless Login by VentraConnect < 1.4.1 - Unauthenticated Account Takeover via Email OTP Brute Force

Assigner: WPScan
Reserved: 24.06.2026 Published: 20.07.2026 Updated: 20.07.2026

The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a working attempt lockout on its passwordless email one-time-password verification, and stores the short numeric codes in plaintext, allowing an unauthenticated attacker who knows a registered email address to brute-force the code and log in as that user, including an administrator, leading to full site takeover.

Product Status

Vendor Unknown
Product Social Login, Passkeys, Magic Link & Email OTP
Versions Default: unaffected
  • affected from 0 to 1.4.1 (excl.)

Credits

  • Pedro Pinho finder
  • WPScan coordinator

References

Problem Types

  • CWE-269 Improper Privilege Management CWE