Magic Login Mail or QR Code

Magic Login Mail or QR Code has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of September 2026. Their average CVSS score is 8.1, and the most serious one scores 8.1 out of 10. Severity breakdown: 0 critical and 1 high.

The most common weakness is Improper Privilege Management, behind 1 of the records (100%).

The one issue recorded for Magic Login Mail or QR Code has a vendor fix available, so running the current release closes it.

All of these findings were reported by ifoundbug. Magic Login Mail or QR Code is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSHigh
8.1/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Magic Login Mail or QR Code vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.1CVE-2026-2144

Magic Login Mail or QR Code <= 2.05 - Unauthenticated Privilege Escalation via Insecure QR Code File Storage

Read the full analysis

Vulnerability Records

1 records
Plugin Profile
Latestv2.07

Magic Login Mail or QR Code

Katsushi Kawamori

Author

Katsushi Kawamori

5.0(3)
100/100
Last Updated
2026-08-16 (28d ago)
Active Installs
100+
Downloads
7,424
Requires WP
4.7+
Requires PHP
8.0+
Tested up to
WP 7.1
Created
2021-12-28 (5y ago)

Enter your email address, and send you an email with a magic link or QR Code to login without a password. Login Login with email address only. Only registered users can login. Password-less login from the magic link or QR code notified in the email. shortcode : [magic_login] action hook : do_action( 'magic_email_send', $emails | array, true | bool ) : To send the magic link simultaneously from the management account. QR code login on the user’s administration screen. Thanks This plugin is a modified version of Passwordless Login. The main changes are the addition of various filter hooks and the addition of the following action hooks. Action hook This is for sending bulk e-mails with a magic link for login to multiple accounts from the management screen. When using this action hook, the URL of the page where the shortcode [magic_login] is placed should be specified in the filter hook &#8216;magic_login_mail_url’. /** ================================================== * To send the magic link simultaneously from the management account. * * @param array $emails Multiple email addresses. * @param bool true Output notifications to the management screen immediately after sending. */ do_action( 'magic_email_send', $emails, true ); Filter hooks /** ================================================== * Filter for magic link url with mail. * */ add_filter( 'magic_login_mail_url', function(){ return 'url'; }, 10, 1 ); /** ================================================== * Currently logged in user link for Magic Login Mail * * @param string $url URL. * @param int $user_id User ID. * @return $url */ add_filter( 'magic_login_mail_user_redirect', 'redirect_url_login_users', 10, 2 ); /** ================================================== * Login user after redirect for Magic Login Mail * * @param string $url URL. * @param int $user_id User ID. * @return $url */ add_filter( 'magic_login_mail_after_login_redirect', 'redirect_url_login_users', 10, 2 ); function redirect_url_login_users( $url, $user_id ){ /* your code */ return $url; } /** ================================================== * Filter for message with shortcode form. * */ add_filter( 'magic_login_mail_success_link_msg', function(){ return 'Message for success.'; }, 10, 1 ); add_filter( 'magic_login_mail_success_login_msg', function(){ return 'Message for success with login.'; }, 10, 1 ); add_filter( 'magic_login_mail_valid_errors', function(){ return 'Message for mail validation error.'; }, 10, 1 ); add_filter( 'magic_login_mail_email_errors', function(){ return 'Message for sent mail error.'; }, 10, 1 ); add_filter( 'magic_login_mail_invalid_token_error', function(){ return 'Message for token error.'; }, 10, 1 ); add_filter( 'magic_login_mail_form_label', function(){ return 'Message for form label.'; }, 10, 1 ); /** ================================================== * Filter for color with shortcode form. * */ add_filter( 'magic_login_mail_success_link_msg_back_color', function(){ return '#e7f7d3'; }, 10, 1 ); add_filter( 'magic_login_mail_success_login_msg_back_color', function(){ return '#e7f7d3'; }, 10, 1 ); add_filter( 'magic_login_mail_valid_errors_back_color', function(){ return '#ffebe8'; }, 10, 1 ); add_filter( 'magic_login_mail_email_errors_back_color', function(){ return '#ffebe8'; }, 10, 1 ); add_filter( 'magic_login_mail_invalid_token_error_back_color', function(){ return '#ffebe8'; }, 10, 1 ); /** ================================================== * Filter for input text size. * */ add_filter( 'magic_login_mail_input_size', function(){ return 17; }, 10, 1 ); /** ================================================== * Filter for class name. * */ add_filter( 'magic_login_mail_notice_class_name', function(){ return 'mynotice'; }, 10, 1 ); add_filter( 'magic_login_mail_form_class_name', function(){ return 'myform'; }, 10, 1 ); add_filter( 'magic_login_mail_label_class_name', function(){ return 'mylabel'; }, 10, 1 ); add_filter( 'magic_login_mail_input_class_name', function(){ return 'myinput'; }, 10, 1 ); add_filter( 'magic_login_mail_submit_class_name', function(){ return 'mysubmit'; }, 10, 1 ); /** ================================================== * Filter for message with mail subject. * */ add_filter( 'magic_login_mail_subject', function(){ return 'subject'; }, 10, 1 ); /** ================================================== * Filter for message with mail. * * @param string $message message. * @param string $url url. * @param string $exp_date_time expiration date and time. */ add_filter( 'magic_login_mail_message', function( $message, $url, $exp_date_time ) { $message .= '<br><br>' . 'You may only log in once using the link above.'; return $message; }, 10, 3 ); /** ================================================== * Filter for login expiration. * */ add_filter( 'magic_login_mail_expiration', function(){ return 10; }, 10, 1 );

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C