PT-2025-38630 · WordPress · Secure Passkeys

Published

2025-09-20

·

Updated

2025-09-20

·

CVE-2025-10305

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Secure Passkeys plugin for WordPress versions up to and including 1.2.1
Description The Secure Passkeys plugin for WordPress is susceptible to unauthorized access due to a missing capability check within the delete passkey() and passkeys list() functions. This allows authenticated attackers with Subscriber-level access or higher to view and delete passkeys.
Recommendations Update the Secure Passkeys plugin to a version beyond 1.2.1.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-10305

Affected Products

Secure Passkeys