Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High0
Medium2
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2025-12-18

CVE-2025-13730 - Openid Connect Generic Client Plugin

The OpenID Connect Generic Client plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'openid_connect_generic_auth_url' shortcode in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

PLUGIN Openid Connect Generic Client

CVE-2025-13730

MEDIUM CVSS 6.4 2025-12-18
Threat Entry Updated 2024-11-21

CVE-2021-24214 - Openid Connect Generic Client Plugin

The OpenID Connect Generic Client WordPress plugin 3.8.0 and 3.8.1 did not sanitise the login error when output back in the login form, leading to a reflected Cross-Site Scripting issue. This issue does not require authentication and can be exploited with the default configuration.

PLUGIN Openid Connect Generic Client

CVE-2021-24214

MEDIUM CVSS 6.1 2021-05-06
Scroll to top