Authentication Bypass Vulnerability in WebinarIgnition Plugin for WordPress
CVE-2025-6441

9.8CRITICAL

What is CVE-2025-6441?

The WebinarIgnition plugin for WordPress has a vulnerability that allows unauthenticated attackers to generate login tokens due to a missing capability check in specific functions. This issue affects all versions up to and including 4.03.31. Attackers can exploit this flaw to create authorization cookies for arbitrary WordPress users, thereby bypassing authentication and potentially compromising user accounts. It is crucial for users of the WebinarIgnition plugin to review their security posture and apply necessary updates to protect against this vulnerability.

Affected Version(s)

Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition * <= 4.03.31

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kenneth Dunn
.
CVE-2025-6441 : Authentication Bypass Vulnerability in WebinarIgnition Plugin for WordPress