Unknown · Social Login · CVE-2026-13142
**Name of the Vulnerable Software and Affected Versions**
Social Login, Passkeys, Magic Link & Email OTP versions prior to 1.4.1
**Description**
An issue exists in the passwordless email one-time-password verification process where rate limiting and attempt lockouts are not enforced. Additionally, the short numeric codes are stored in plaintext. This allows an unauthenticated attacker with knowledge of a registered email address to brute-force the verification code and gain unauthorized access to any user account, including those with administrator privileges, resulting in a full site takeover.
**Recommendations**
Update to version 1.4.1 or later.