Junglewise Threat Intelligence

CVE-2026-14495: DoLogin Security authentication bypass via insufficient randomness

CVE-2026-14495 · Severity: high · CVSS 8.8 · Published 2026-07-08

Executive brief

The DoLogin Security plugin for WordPress, which provides enhanced login security and passwordless authentication, contains a flaw in how it generates secure login links. An attacker can predict these secret links due to weak mathematical randomness used by the software. If a user has an active passwordless login link, an attacker could bypass authentication entirely and gain full access to the site, including administrator accounts.

Technical details

The vulnerability stems from the `dologin\s::rrand()` function seeding the Mersenne Twister (PRNG) with `microtime()` in a way that discards integer seconds, reducing the entropy to approximately 20 bits (~10^6 values). Because the 32-character magic-link tokens are generated sequentially from this weak seed, they are deterministic and guessable. The `Pswdless::try_login()` function, hooked to `init`, allows unauthenticated access and uses a non-constant-time comparison operator (`!=`) for the hash. Furthermore, it bypasses `wp_authenticate()`, meaning the plugin's own lockout mechanisms are not triggered during a brute-force attack. Successful exploitation requires a valid, unexpired passwordless link to exist for the target account.

Affected products

  • wpdo5ea DoLogin Security up to, and including, 4.3

Timeline

  • 2026-07-08: advisory: NVD publication date

References