Authentication Bypass Vulnerability in WebinarIgnition Plugin for WordPress
CVE-2025-6441
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 July 2025
What is CVE-2025-6441?
The WebinarIgnition plugin for WordPress has a vulnerability that allows unauthenticated attackers to generate login tokens due to a missing capability check in specific functions. This issue affects all versions up to and including 4.03.31. Attackers can exploit this flaw to create authorization cookies for arbitrary WordPress users, thereby bypassing authentication and potentially compromising user accounts. It is crucial for users of the WebinarIgnition plugin to review their security posture and apply necessary updates to protect against this vulnerability.
Affected Version(s)
Webinar Solution: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition * <= 4.03.31