<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Social Login, Passkeys, Magic Link &amp; Email OTP – Passwordless Login (&lt;= 1.4.3) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/social-login-passkeys-magic-link--email-otp--passwordless-login--1.4.3/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 12 Aug 2026 03:55:10 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/social-login-passkeys-magic-link--email-otp--passwordless-login--1.4.3/feed.xml" rel="self" type="application/rss+xml"/><item><title>Authentication Bypass in VentraConnect Passwordless Login Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-08-ventraconnect-auth-bypass/</link><pubDate>Wed, 12 Aug 2026 03:55:10 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-ventraconnect-auth-bypass/</guid><description>An authentication bypass vulnerability in the VentraConnect WordPress plugin allows unauthenticated attackers to hijack user accounts, including administrators, by spoofing verified email claims during Spotify OAuth flows.</description><content:encoded><![CDATA[<p>The VentraConnect 'Social Login, Passkeys, Magic Link &amp; Email OTP' plugin for WordPress (all versions up to and including 1.4.3) contains a critical authentication bypass vulnerability identified as CVE-2026-18961. The vulnerability stems from improper validation of OAuth responses from the Spotify API. Specifically, the plugin's <code>Generic::normalize_common()</code> method consumes the email field from the Spotify <code>/v1/me</code> endpoint without verifying the associated <code>email_verified</code> claim. The subsequent <code>User_Links::link_or_login_user()</code> method uses this unverified email to identify and log in WordPress users via <code>wp_set_auth_cookie()</code> without requiring an additional ownership challenge or provider-side verification gate. An attacker can create a Spotify account with a target victim's email address and leverage the OAuth flow to masquerade as the target user, effectively gaining unauthorized access to the WordPress site. If the target is an Administrator, the attacker gains full site control.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for complete site takeover. By targeting the email addresses of site administrators, an attacker can bypass all authentication mechanisms to gain administrative privileges. This vulnerability exposes affected websites to full administrative compromise, data exfiltration, and persistent backdooring, as the WordPress ecosystem often ties authentication to site-wide configuration and content management.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the 'Social Login, Passkeys, Magic Link &amp; Email OTP' plugin to a version released after 1.4.3 immediately.</li>
<li>If an update is not available, disable the Spotify social login integration within the plugin settings until a patch is applied.</li>
<li>Review WordPress user account activity and session logs for unusual login patterns or modifications to administrative account profiles occurring during the period the plugin was active and unpatched.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>