Impact
The WordPress plugin Social Login, Passkeys, Magic Link & Email OTP before version 1.4.1 lacks rate limiting on its password‑based email OTP verification and stores the short numeric codes in plaintext. This is a CWE-269 weak access control vulnerability. An attacker who can obtain a user’s email address can repeatedly request a one‑time password and try all possible codes until the correct one is found, allowing the attacker to log in as that user, including administrators, achieving a full site takeover.
Affected Systems
WordPress sites running the Social Login, Passkeys, Magic Link & Email OTP plugin with a version earlier than 1.4.1.
Risk and Exploitability
The CVSS score of 8.1 reflects the severe impact. The EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalog, but the lack of attempt lockout and plaintext code storage make brute‑force attacks technically straightforward once an email address is known. The impact is severe, granting complete control of the affected site.
OpenCVE Enrichment