Impact
The VentraConnect Social Login plugin for WordPress allows unauthenticated attackers to bypass authentication by exploiting the lack of email verification in the Spotify OAuth flow. The plugin copies the unverified email field from Spotify’s /v1/me endpoint into its user profile without checking the email_verified flag, then directly uses that email to authenticate the user and issue a persistent cookie. As a result, an attacker who controls the OAuth callback can log in as any existing WordPress user, including administrators, by simply supplying a known email address, thereby gaining full administrative access to the site.
Affected Systems
All installations of the VentraConnect Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login WordPress plugin with version 1.4.3 or earlier are affected. This includes any WordPress site that has the plugin activated and relies on Spotify as an authentication provider.
Risk and Exploitability
The vulnerability has a CVSS score of 8.1, indicating high severity. The EPSS score is less than 1 %, suggesting a very low probability that attackers are actively exploiting this flaw, and the issue is not listed in the CISA KEV catalog. However, the attack path is straightforward and requires only control of the Spotify OAuth callback, allowing unauthenticated users to impersonate any site user. Without mitigation, attackers could gain administrative privileges and compromise the entire WordPress installation.
OpenCVE Enrichment