Authentication Bypass Vulnerability in OwnID Passwordless Login Plugin for WordPress
CVE-2025-10294

9.8CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 October 2025

What is CVE-2025-10294?

The OwnID Passwordless Login plugin for WordPress has a significant security flaw that allows unauthenticated attackers to bypass authentication mechanisms. This occurs due to the plugin's failure to validate the 'ownid_shared_secret' value before allowing user authentication via JWT. As a result, attackers can log in as any user, including administrators, particularly on installations where the plugin remains misconfigured. Users of the plugin should address this vulnerability by ensuring proper configuration and applying any relevant updates.

Affected Version(s)

OwnID Passwordless Login * <= 1.3.4

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jonas Benjamin Friedli
.
CVE-2025-10294 : Authentication Bypass Vulnerability in OwnID Passwordless Login Plugin for WordPress