Authentication Bypass Vulnerability in OwnID Passwordless Login Plugin for WordPress
CVE-2025-10294
What is CVE-2025-10294?
The OwnID Passwordless Login plugin for WordPress has a significant security flaw that allows unauthenticated attackers to bypass authentication mechanisms. This occurs due to the plugin's failure to validate the 'ownid_shared_secret' value before allowing user authentication via JWT. As a result, attackers can log in as any user, including administrators, particularly on installations where the plugin remains misconfigured. Users of the plugin should address this vulnerability by ensuring proper configuration and applying any relevant updates.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
OwnID Passwordless Login * <= 1.3.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved