CyberRota Analysis
AI-GeneratedThe Social Login, Passkeys, Magic Link & Email OTP WordPress plugin prior to version 1.4.1 is vulnerable due to a lack of rate limiting and attempt lockout on its passwordless email OTP verification, coupled with the storage of short numeric codes in plaintext. This allows unauthenticated attackers to brute-force the OTP, potentially gaining unauthorized access to user accounts, including administrative accounts, resulting in complete site compromise. WordPress site administrators using this plugin should prioritize updating to version 1.4.1 or later to mitigate this critical vulnerability.
Original NVD Description
The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a working attempt lockout on its passwordless email one-time-password verification, and stores the short numeric codes in plaintext, allowing an unauthenticated attacker who knows a registered email address to brute-force the code and log in as that user, including an administrator, leading to full site takeover.