Skip to main content
brighter websites logoBrighter Websites Logo White

I Shut down a Targeted Magic link login Vulnerability

Author

Table Of Contents

What Happened

A routine server monitoring flagged unusual login activity on a dormant staging site, hundreds of requests in short bursts, targeting a single account, sustained over several days.

The Paws For Support project had wrapped some time earlier. Ongoing maintenance had transitioned to a local specialist, which made sense for the client’s day-to-day needs. The staging environment had been left active on the server pending confirmation it was no longer needed, standard practice until a client or their team signs off on removal.

No active work. No recent logins. No reason anyone would have been looking.

That’s exactly when these things get missed.

WordPress login screen with magic link option targeted by repeated bot login attempts via exposed username
Bots scraped a public username from the WordPress API and repeatedly hit the magic link login endpoint to force access

What I Found

The first step was stopping the noise, HTTP authentication added to the staging domain, bot traffic stopped immediately.

The second step was understanding why that specific account was being targeted.

WordPress automatically generates a public username slug from the email address used during account setup. In this case, name.surname@gmail.com had become the publicly visible username name.surname exposed at the site’s default REST API endpoint:

/wp-json/wp/v2/users

Every other user account on the site had been set up with anonymised credentials. Randomised slugs like huio_89i7 were specifically used to prevent this kind of exposure. Those accounts appeared in the same API response and required no further action. The one account that stood out was the anomaly, not the norm.

The bots hadn’t guessed the email address. They had scraped it directly from WordPress’s default public API, then used it to reconstruct a valid login target and hammer the magic link endpoint repeatedly.

HTTP authentication login prompt protecting a staging WordPress site from unauthorised access
Basic HTTP authentication immediately stopped bot traffic and blocked access to the staging environment

This isn’t a rookie configuration mistake. It’s a WordPress default behaviour that most developers never think to lock down, and most site owners would have no reason to know exists.

One additional detail worth noting: the Site Admin email address listed in WordPress Settings had no corresponding user account. The account appears to have been added during the original build and removed during the handover transition. The email address persisted in settings but the user no longer existed. In this case that turned out to be an accidental safeguard. There was no valid account to compromise. But that’s luck, not a security strategy.

Three Vulnerabilities Worth Understanding

Magic link endpoints are high-value targets.

A magic link login URL is more attractive to attackers than standard wp-login.php because it bypasses password authentication entirely. Properly anonymised usernames neutralise this risk regardless of which login plugin is in use, the attacker can’t target what they can’t identify.

A ghost leak is still a vulnerability.

Even without a live user account, the email address was visible in the REST API response. Partial exposure is still exposure. The only thing preventing a successful login attempt was the absence of a valid account on the other end, not any deliberate security measure.

Staging sites are attack practice ranges.

Staging environments are typically configured with relaxed security to make development easier to work in. If credentials are shared between staging and production, an attacker can run brute force attempts on staging without triggering the lockouts and rate limiting protecting the live site, then use those credentials to walk straight into the primary domain undetected. Keeping credentials separated across environments isn’t optional, it’s foundational.

What I Flagged for the Live Site

Once the staging site was secured, I shared the full findings with the client and their current designer, along with a checklist for their live domain:

  • Is /wp-json/wp/v2/users publicly accessible?
  • Are any username slugs derived from email addresses?
  • Is the magic link login endpoint rate limited or otherwise protected?
  • Does the Site Admin email in Settings > General point to an active, secured account?
  • Are staging and production credentials fully separated?

Acting on their live site wasn’t my place, that’s their designer’s domain now, and that’s the right way to work. My role was to catch it, document it clearly, and make sure the right people had what they needed to act.

Subscribe to our blog or get in touch.

Get in touch with with Vanessa. Your Ballarat website strategist, designer and developer.

Occasional emails from Vanessa at Brighter Websites about AI, SEO, Website Marketing for regional service businesses.  
See what we have done

More Articles

Discover more expert insights to the latest Web Design and SEO trends, these curated blog posts are designed to broaden your horizons and spark your imagination.

SEO + Web Design
Digital data trust highway leading towards bright horizon, Representing the path towards future visibility through a trust building proof library

Two Quick Fixes That Doubled Click-Through Rates for Mobile Massage Website

A solo massage business owner in Daylesford was losing half their Google traffic due to an insecure website link in their Google Business Profile. By fixing just two issues—switching to HTTPS and optimizing meta tags—they nearly doubled their click-through rate from 2% to 11% in 24 hours, proving that sometimes small, strategic fixes deliver outsized results.

Artificial Intelligence (AI) and Generative AI

Using the Agent Connector Web Design with AI in Breakdance 3.0.0

Breakdance 3.0 beta’s Agent Connector lets AI agents build and edit native site data, preserving selectors, responsive rules, variables, fonts, and keyframes when source designs use structured tokens. This firsthand exploration across six websites also covers selector folders, custom AI workflow skills, conversion pitfalls, beta limitations, and the evolving collaboration between designer and agent.

Web Design
AI-generated design system layout showing typography scales, colour tokens, and spacing rules for a website build

AI Design Systems for Websites: How to Use AI to Build Better Website Rules Before You Build the Site

A website design system is a collection of reusable coded rules defining how a site looks and behaves through typography, spacing, color tokens, and components. Unlike branding which establishes emotional identity, design systems translate that identity into buildable infrastructure. AI can generate structured design systems from logos and colors in minutes, but human judgment is essential for refining accessibility, eliminating redundancies, and ensuring production-ready foundations before building pages.

AI Citation Strategy
Diagram showing local business visibility across Google Maps, AI tools, social platforms and review sites in a zero-click search world

Search Everywhere Optimisation: How Local Businesses Win in a Zero-Click Search World

Search Everywhere Optimisation helps businesses become visible across all platforms customers use to research purchases, from Google Maps to AI tools like ChatGPT. With 68% of searches now ending without clicks, success depends on clear business information, consistent details across platforms, credible proof and conversion paths that work outside your website.

Uh oh, the form hit a snag.

Looks like something didn’t load right.

Give it another go, or flick us a message at support@brighterwebsites.com.au  if it keeps failing. We’ll fix it faster than you can say “cache clear.”

You can phone Vanessa too - she doesn't mind a chat 0412401933