Description
The OwnID Passwordless Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.3.4. This is due to the plugin not properly checking if the ownid_shared_secret value is empty prior to authenticating a user via JWT. This makes it possible for unauthenticated attackers to log in as other users, including administrators, on instances where the plugin has not been fully configured yet.
Problem types
CWE-288 Authentication Bypass Using an Alternate Path or Channel
Product status
*
Timeline
2025-10-14: | Disclosed |
Credits
Jonas Benjamin Friedli
References
www.wordfence.com/...-e9b8-4a87-b1c7-0dc272850cbd?source=cve
wordpress.org/plugins/ownid-passwordless-login/