Known vulnerabilities in WP-WebAuthn
WP-WebAuthn enables passwordless login through FIDO2 and U2F devices like Passkey, FaceID or Windows Hello for your site.
3Reported vulnerabilities
6.4Highest CVSS score
1.4.1Latest version
2,000+Active installs
What to do now
Update WP-WebAuthn to 1.3.2 or later.
2 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2024-47650 | Medium | 0.2% | 1.3.1 and earlier | 1.3.2 |
September 30, 2024 |
| CVE-2025-13910 | Medium | 0.3% | 0 to 1.3.4 (inclusive) | — | March 21, 2026 |
| CVE-2024-9023 | Medium | 0.4% | 1.3.1 and earlier | 1.3.4 |
September 28, 2024 |