Social Login, Passkeys, Magic Link & Email OTP < 1.4.1 - Unauthenticated Account Takeover via OTP Brute Force
2026-06-23 00:00
WPscanStrategic Overview
StatusPatched in 1.4.1
Affected Version
< 1.4.1CVSS9.8Critical
CVE
CVE-2026-13142Vulnerability Overview
The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Privilege Escalation via brute force in all versions up to 1.4.1 (exclusive). This makes it possible for unauthenticated attackers to brute force OTP tokens and gain access to administrative level accounts.
Technical Analysis
REMEDIATION: Update to version 1.4.1, or a newer patched version --- IDENTIFIER: CWE-269 (Improper Privilege Management) The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C