Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect <= 1.4.3 - Unauthenticated Authentication Bypass via Spotify OAuth Callback
high
The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass via Unverified Provider Email in all versions up to, and including, 1.4.3. This is due to the plugin trusting the unverified email field returned by Spotify's /v1/me endpo...
- CVSS:
- 8.1
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.4
- Disclosed:
- Aug 11, 2026
CVE-2026-18961 on NVD →
Social Login, Passkeys, Magic Link & Email OTP < 1.4.1 - Unauthenticated Account Takeover via OTP Brute Force
critical
The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Privilege Escalation via brute force in all versions up to 1.4.1 (exclusive). This makes it possible for unauthenticated attackers to brute force OTP tokens and gain access to administrative le...
- CVSS:
- 9.8
- Affected:
- up to 1.4.1
- Fixed in:
- 1.4.1
- Disclosed:
- Jun 23, 2026
CVE-2026-13142 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database