Horizon Alert
Summary of the vulnerability and why it matters
This advisory highlights a critical vulnerability in the OwnID Passwordless Login plugin for WordPress, which could allow unauthenticated attackers to bypass login procedures and gain access to user accounts, including administrative ones. The issue stems from improper validation of a security credential, making it possible for unauthorized individuals to log in if the plugin is not fully configured.
- Bypasses login to access user accounts.
- Critical for any WordPress sites using this plugin.
- Confirm relevance and exposure of this authentication flaw.
Attack Path
How an attacker could exploit the issue
An attacker can bypass authentication on a WordPress site by exploiting the OwnID Passwordless Login plugin. If the plugin is not fully configured, an attacker can send a request that tricks the plugin into granting them access as another user, potentially an administrator. This bypass allows them to log in without valid credentials.
- Unauthenticated access to the website.
- Empty shared secret bypasses authentication.
- Full account takeover.
Live Threat
Current exploitation, exposure, and threat context
When an OwnID Passwordless Login plugin is not fully configured, unauthenticated attackers could bypass authentication. This could allow them to log in as any user, including administrators, to the affected WordPress instance.
- User account access at risk.
- Unauthenticated login possible.
- Unauthorized user access to system.
Operational Fix
Recommended remediation, mitigation, and detection steps
The OwnID Passwordless Login plugin for WordPress, used for authentication, is vulnerable. This issue likely falls under the responsibility of the WordPress site owner or administrator, who manages the plugin and its configuration. The first practical step is to identify all WordPress instances using this plugin, assess their exposure and business criticality, and then coordinate with the site owner for remediation.
- WordPress site owners should address this.
- Verify plugin configuration and reachability.
- Plan remediation based on risk assessment.