Authentication Bypass Vulnerability in OwnID Passwordless Login Plugin for WordPress
CVE-2025-10294
9.8CRITICAL
What is CVE-2025-10294?
The OwnID Passwordless Login plugin for WordPress has a significant security flaw that allows unauthenticated attackers to bypass authentication mechanisms. This occurs due to the plugin's failure to validate the 'ownid_shared_secret' value before allowing user authentication via JWT. As a result, attackers can log in as any user, including administrators, particularly on installations where the plugin remains misconfigured. Users of the plugin should address this vulnerability by ensuring proper configuration and applying any relevant updates.
Affected Version(s)
OwnID Passwordless Login * <= 1.3.4