CVE-2025-10305: CWE-862 Missing Authorization in endisha Secure Passkeys
The Secure Passkeys plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the delete_passkey() and passkeys_list() function in all versions up to, and including, 1.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view and delete passkeys.
CVE-2025-10305: CWE-862 Missing Authorization in endisha Secure Passkeys
Description
The Secure Passkeys plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the delete_passkey() and passkeys_list() function in all versions up to, and including, 1.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to view and delete passkeys.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- Wordfence
- Date Reserved
- 2025-09-11T22:04:22.079Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 68cf42444a0b186b9321b040
Added to database: 9/21/2025, 12:09:40 AM
Last updated: 9/21/2025, 12:09:40 AM
Views: 1
Related Threats
CVE-2025-9949: CWE-352 Cross-Site Request Forgery (CSRF) in webraketen Internal Links Manager
MediumCVE-2025-10489: CWE-862 Missing Authorization in brainstormforce SureForms – Drag and Drop Contact Form Builder – Multi-step Forms, Conversational Forms and more
MediumCVE-2025-10181: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in dartiss Draft List
MediumCVE-2025-10002: CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in clickwhale ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages
MediumCVE-2025-10756: Buffer Overflow in UTT HiPER 840G
HighActions
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.