SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-13142

HIGH · CVSS 8.1 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin prior to version 1.4.1 is vulnerable due to a lack of rate limiting and attempt lockout on its passwordless email OTP verification, coupled with the storage of short numeric codes in plaintext. This allows unauthenticated attackers to brute-force the OTP, potentially gaining unauthorized access to user accounts, including administrative accounts, resulting in complete site compromise. WordPress site administrators using this plugin should prioritize updating to version 1.4.1 or later to mitigate this critical vulnerability.

CVE
CVE-2026-13142
Severity
HIGH
CVSS
8.1
EPSS
0.23%
WordPress

Original NVD Description

The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a working attempt lockout on its passwordless email one-time-password verification, and stores the short numeric codes in plaintext, allowing an unauthenticated attacker who knows a registered email address to brute-force the code and log in as that user, including an administrator, leading to full site takeover.