plugin

Ownid Passwordless Login Vulnerabilities

1 known security issue reported for the Ownid Passwordless Login WordPress plugin. Most recent disclosed Oct 14, 2025.

1 critical

Running Ownid Passwordless Login on your site? Check whether your installed version is affected.

Scan your site free

OwnID Passwordless Login <= 1.3.4 - Authentication Bypass

critical

The OwnID Passwordless Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.3.4. This is due to the plugin not properly checking if the ownid_shared_secret value is empty prior to authenticating a user via JWT. This makes it possible for unauthenticated attackers to...

CVSS:
9.8
Affected:
up to 1.3.4
Fix:
No patched version reported
Disclosed:
Oct 14, 2025

CVE-2025-10294 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database