External risk intelligence

OwnID Passwordless Login Authentication Bypass Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-10294

The vulnerability affects a WordPress plugin designed to handle user authentication (login). WordPress sites are commonly deployed as public-facing web applications. Because this plugin operates at the authentication layer of a web-accessible platform, the vulnerable surface is commonly exposed to the internet in typical deployments.

Authentication Bypass

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory highlights a critical vulnerability in the OwnID Passwordless Login plugin for WordPress, which could allow unauthenticated attackers to bypass login procedures and gain access to user accounts, including administrative ones. The issue stems from improper validation of a security credential, making it possible for unauthorized individuals to log in if the plugin is not fully configured.

  • Bypasses login to access user accounts.
  • Critical for any WordPress sites using this plugin.
  • Confirm relevance and exposure of this authentication flaw.

Attack Path

How an attacker could exploit the issue

An attacker can bypass authentication on a WordPress site by exploiting the OwnID Passwordless Login plugin. If the plugin is not fully configured, an attacker can send a request that tricks the plugin into granting them access as another user, potentially an administrator. This bypass allows them to log in without valid credentials.

  • Unauthenticated access to the website.
  • Empty shared secret bypasses authentication.
  • Full account takeover.

Live Threat

Current exploitation, exposure, and threat context

When an OwnID Passwordless Login plugin is not fully configured, unauthenticated attackers could bypass authentication. This could allow them to log in as any user, including administrators, to the affected WordPress instance.

  • User account access at risk.
  • Unauthenticated login possible.
  • Unauthorized user access to system.

Operational Fix

Recommended remediation, mitigation, and detection steps

The OwnID Passwordless Login plugin for WordPress, used for authentication, is vulnerable. This issue likely falls under the responsibility of the WordPress site owner or administrator, who manages the plugin and its configuration. The first practical step is to identify all WordPress instances using this plugin, assess their exposure and business criticality, and then coordinate with the site owner for remediation.

  • WordPress site owners should address this.
  • Verify plugin configuration and reachability.
  • Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the OwnID Passwordless Login plugin?

It is a WordPress extension designed to replace traditional username and password logins with passwordless authentication methods. It streamlines user access by utilizing JSON Web Tokens (JWT) for identity verification, allowing users to sign in without managing standard credentials. Because it integrates directly into the WordPress authentication workflow, it becomes a central component for managing user sessions on sites where it is active.

What does CWE-288 mean for CVE-2025-10294?

CWE-288 refers to authentication bypass by assuming the existence of an alternative, insecure path to verify a user's identity. In this specific case, the plugin fails to verify if a shared secret is present before accepting a login request. By missing this check, the system essentially trusts an empty or missing credential, allowing the plugin to mistakenly validate unauthorized login attempts as legitimate.

How do attackers trigger this vulnerability?

The flaw is triggered when the plugin is installed but not fully configured, specifically when the required shared secret has not been set up. An attacker does not need existing credentials to exploit this; they simply send a crafted request to the site. If the plugin has not completed its setup process, it defaults to an insecure state that accepts these malicious requests, meaning fully configured and properly set up instances are not susceptible to this specific bypass.

Is my site at risk according to Halo Surface Signal?

Yes, if you use this plugin on a public-facing website, you should be concerned. Halo Surface Signal identifies this as a highly relevant threat because WordPress sites are typically exposed to the internet, and this vulnerability resides directly within the authentication layer. Since the plugin handles user logins, any internet-accessible WordPress instance using an unconfigured version of this software presents an open door for unauthorized account access.

Do I need to check my WordPress plugin configuration?

Yes, you should immediately inventory your WordPress instances to see if this plugin is installed. The primary goal is to determine if the plugin is currently in use and whether it has been fully configured with the necessary security credentials. If you find the plugin, consult the site administrator to verify its setup status and coordinate any required updates or configuration changes to close this authentication gap.

References