Social Login, Passkeys, Magic Link & Email OTP < 1.4.1 - Unauthenticated Account Takeover via OTP Brute Force

2026-06-23 00:00
WPscan

Vulnerability Overview

The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Privilege Escalation via brute force in all versions up to 1.4.1 (exclusive). This makes it possible for unauthenticated attackers to brute force OTP tokens and gain access to administrative level accounts.

Technical Analysis

REMEDIATION: Update to version 1.4.1, or a newer patched version --- IDENTIFIER: CWE-269 (Improper Privilege Management) The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C