{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/social-login-passkeys-magic-link--email-otp--passwordless-login--1.4.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-18961"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Social Login, Passkeys, Magic Link \u0026 Email OTP – Passwordless Login (\u003c= 1.4.3)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["VentraConnect"],"content_html":"\u003cp\u003eThe VentraConnect 'Social Login, Passkeys, Magic Link \u0026amp; Email OTP' plugin for WordPress (all versions up to and including 1.4.3) contains a critical authentication bypass vulnerability identified as CVE-2026-18961. The vulnerability stems from improper validation of OAuth responses from the Spotify API. Specifically, the plugin's \u003ccode\u003eGeneric::normalize_common()\u003c/code\u003e method consumes the email field from the Spotify \u003ccode\u003e/v1/me\u003c/code\u003e endpoint without verifying the associated \u003ccode\u003eemail_verified\u003c/code\u003e claim. The subsequent \u003ccode\u003eUser_Links::link_or_login_user()\u003c/code\u003e method uses this unverified email to identify and log in WordPress users via \u003ccode\u003ewp_set_auth_cookie()\u003c/code\u003e without requiring an additional ownership challenge or provider-side verification gate. An attacker can create a Spotify account with a target victim's email address and leverage the OAuth flow to masquerade as the target user, effectively gaining unauthorized access to the WordPress site. If the target is an Administrator, the attacker gains full site control.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for complete site takeover. By targeting the email addresses of site administrators, an attacker can bypass all authentication mechanisms to gain administrative privileges. This vulnerability exposes affected websites to full administrative compromise, data exfiltration, and persistent backdooring, as the WordPress ecosystem often ties authentication to site-wide configuration and content management.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the 'Social Login, Passkeys, Magic Link \u0026amp; Email OTP' plugin to a version released after 1.4.3 immediately.\u003c/li\u003e\n\u003cli\u003eIf an update is not available, disable the Spotify social login integration within the plugin settings until a patch is applied.\u003c/li\u003e\n\u003cli\u003eReview WordPress user account activity and session logs for unusual login patterns or modifications to administrative account profiles occurring during the period the plugin was active and unpatched.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-12T03:55:10Z","date_published":"2026-08-12T03:55:10Z","id":"https://feed.craftedsignal.io/briefs/2026-08-ventraconnect-auth-bypass/","summary":"An authentication bypass vulnerability in the VentraConnect WordPress plugin allows unauthenticated attackers to hijack user accounts, including administrators, by spoofing verified email claims during Spotify OAuth flows.","title":"Authentication Bypass in VentraConnect Passwordless Login Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-ventraconnect-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Social Login, Passkeys, Magic Link \u0026 Email OTP – Passwordless Login (\u003c= 1.4.3)","version":"https://jsonfeed.org/version/1.1"}