Authentication Bypass Vulnerability in WebinarIgnition Plugin for WordPress
CVE-2025-6441
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 July 2025
What is CVE-2025-6441?
The WebinarIgnition plugin for WordPress has a vulnerability that allows unauthenticated attackers to generate login tokens due to a missing capability check in specific functions. This issue affects all versions up to and including 4.03.31. Attackers can exploit this flaw to create authorization cookies for arbitrary WordPress users, thereby bypassing authentication and potentially compromising user accounts. It is crucial for users of the WebinarIgnition plugin to review their security posture and apply necessary updates to protect against this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition * <= 4.03.31
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved