Executive brief
The DoLogin Security plugin for WordPress, which provides enhanced login security and passwordless authentication, contains a flaw in how it generates secure login links. An attacker can predict these secret links due to weak mathematical randomness used by the software. If a user has an active passwordless login link, an attacker could bypass authentication entirely and gain full access to the site, including administrator accounts.
Technical details
The vulnerability stems from the `dologin\s::rrand()` function seeding the Mersenne Twister (PRNG) with `microtime()` in a way that discards integer seconds, reducing the entropy to approximately 20 bits (~10^6 values). Because the 32-character magic-link tokens are generated sequentially from this weak seed, they are deterministic and guessable. The `Pswdless::try_login()` function, hooked to `init`, allows unauthenticated access and uses a non-constant-time comparison operator (`!=`) for the hash. Furthermore, it bypasses `wp_authenticate()`, meaning the plugin's own lockout mechanisms are not triggered during a brute-force attack. Successful exploitation requires a valid, unexpired passwordless link to exist for the target account.
Affected products
- wpdo5ea DoLogin Security up to, and including, 4.3
Timeline
- 2026-07-08: advisory: NVD publication date
References
- https://plugins.trac.wordpress.org/browser/dologin/tags/4.3/src/pswdless.cls.php
- https://plugins.trac.wordpress.org/browser/dologin/tags/4.3/src/pswdless.cls.php
- https://plugins.trac.wordpress.org/browser/dologin/tags/4.3/src/pswdless.cls.php
- https://plugins.trac.wordpress.org/browser/dologin/tags/4.3/src/s.cls.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/16bce371-b524-48eb-8537-3f9df802abd3?source=cve