CVE-2026-2144Disclosure

LOWCVSS 8.1 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Magic Login Mail or QR Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.05. This is due to the plugin storing the magic login QR code image with a predictable, static filename (QR_Code.png) in the publicly accessible WordPress uploads directory during the email sending process. The file is only deleted after wp_mail() completes, creating an exploitable race condition window. This makes it possible for unauthenticated attackers to trigger a login link request for any user, including administrators, and then exploit the race condition between QR code file creation and deletion to obtain the login URL encoded in the QR code, thereby gaining unauthorized access to the targeted user's account.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-14: 3Technical Details · 2026-02-14: 202-14
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-2144 The Magic Login Mail or QR Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.05. This is due to the plugin storing… https://www.cve.org/CVERecord?id=CVE-2026-2144

    Post summary

    The Magic Login Mail or QR Code plugin for WordPress is vulnerable to privilege escalation in all versions up to 2.05, as documented in the CVE record.

    00010157
    56.5K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-2144 📊 Severity: 8.1 🚨 Risk Level: High 🧩 Affects: Wordpress Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-2144 #CVE-2026-2144 #CVE #High #Wordpress #CyberSecurity #InfoSec https://t.co/tBpND3yS1L

    Post summary

    A new WordPress CVE-2026-2144 with severity 8.1 is announced, but no exploitation details, patch information, or technical specifics are provided.

    0000029
    56 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-2144 - High The Magic Login Mail or QR Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.05. This is due to the plugin storing the magic login QR code... https://www.thehackerwire.com/vulnerability/CVE-2026-2144/ https://t.co/V8cvkVzpLP

    Post summary

    The Magic Login Mail or QR Code plugin for WordPress has a privilege escalation vulnerability in all versions up to 2.05 due to insecure storage of the magic login QR code. No exploit or patch details are provided.

    0000046
    112 followersView on X

Explore more