
CVE-2025-13910 The WP-WebAuthn plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the `wwa_auth` AJAX endpoint in all versions up to, and includin… https://www.cve.org/CVERecord?id=CVE-2025-13910
Post summary
The text announces a new CVE (WP-WebAuthn XSS flaw) and provides basic technical details without further claims of exploitation, patches, or a PoC.
