CVE-2026-18961 | VentraConnect Social Login up to 1.4.3 on WordPress Spotify OAuth normalize_common email improper authentication

SecurityVulns

A vulnerability classified as critical has been found in VentraConnect Social Login, Passkeys and Magic Link & Email OTP Plugin up to 1.4.3 on WordPress. Affected by this vulnerability is the function Generic::normalize_common of the component Spotify OAuth. Performing a manipulation of the argument email results in improper authentication.

This vulnerability is known as CVE-2026-18961. Remote exploitation of the attack is possible. No exploit is available.VulDB Recent EntriesRead More