CVE-2026-2144

Magic Login Mail or QR Code <= 2.05 - Unauthenticated Privilege Escalation via Insecure QR Code File Storage

2026-02-13 16:21
ifoundbug

Strategic Overview

Status
Patched in 2.06
Affected Version
<= 2.05
CVSS
8.1High
Weakness type
CWE-269 · Improper Privilege Management
CVE
CVE-2026-2144
View all Magic Login Mail or QR Code vulnerabilities

At a glance

CVE-2026-2144 is a high-severity Improper Privilege Management vulnerability in the Magic Login Mail or QR Code WordPress plugin, affecting versions <= 2.05. It carries a CVSS score of 8.1 (reachable over the network; high confidentiality, integrity, availability impact). Exploitation requires no authentication. The issue is fixed in version 2.06; sites on affected versions should update now. Disclosed February 2026, reported by ifoundbug.

Vulnerability Overview

The Magic Login Mail or QR Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.05. This is due to the plugin storing the magic login QR code image with a predictable, static filename (QR_Code.png) in the publicly accessible WordPress uploads directory during the email sending process. The file is only deleted after wp_mail() completes, creating an exploitable race condition window. This makes it possible for unauthenticated attackers to trigger a login link request for any user, including administrators, and then exploit the race condition between QR code file creation and deletion to obtain the login URL encoded in the QR code, thereby gaining unauthorized access to the targeted user's account.

Technical Analysis

The vector marks this flaw as remotely reachable over the network, and no privileges on the target site, and no interaction from a victim user. A successful exploit has high impact on confidentiality, integrity, availability — full site compromise territory.

CWE-269: Improper Privilege Management

Magic Login Mail or QR Code <= 2.05 carries this weakness at wp_mail(), and reaching it takes no account at all. Improper privilege management means the code lets an account end up with capabilities its role should not have.

It converts a low-privileged account into an administrative one, which makes every other restriction on the site irrelevant. For Magic Login Mail or QR Code the fix is 2.06: builds <= 2.05 are affected, anything from 2.06 onward is not.

Remediation

Update to version 2.06, or a newer patched version

How does WordSec protect against this?

This one needs no account at all, which puts it outside what login hardening can reach; WordSec's login security narrows the account-level paths around it, and the firewall is what inspects the request itself. None of that substitutes for the fix: Magic Login Mail or QR Code 2.06 closes this, and updating the plugin is the step that ends it.

  • Login Security
  • Alerts

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C