plugin

Magic Login Mail Vulnerabilities

1 known security issue reported for the Magic Login Mail WordPress plugin. Most recent disclosed Feb 13, 2026.

1 high

Running Magic Login Mail on your site? Check whether your installed version is affected.

Scan your site free

Magic Login Mail or QR Code <= 2.05 - Unauthenticated Privilege Escalation via Insecure QR Code File Storage

high

The Magic Login Mail or QR Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.05. This is due to the plugin storing the magic login QR code image with a predictable, static filename (QR_Code.png) in the publicly accessible WordPress uploads directory during the email...

CVSS:
8.1
Affected:
up to 2.05
Fixed in:
2.06
Disclosed:
Feb 13, 2026

CVE-2026-2144 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database