Vulnerabilities and security researches fordaggerhart-openid-connect-generic daggerhart-openid-connect-generic
Direction: descendingJan 11, 2026
OpenID Connect Generic Client # CVE-2025-13730
- CVE, Research URL
- Home page URL
- Application
- Date
- Dec 18, 2025
- Research Description
- The OpenID Connect Generic Client plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'openid_connect_generic_auth_url' shortcode in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
- Affected versions
-
max 3.10.1.
- Status
-
vulnerable
Jun 07, 2024
OpenID Connect Generic Client # CVE-2021-24214
- CVE, Research URL
- Home page URL
- Application
- Date
- May 06, 2021
- Research Description
- The OpenID Connect Generic Client WordPress plugin 3.8.0 and 3.8.1 did not sanitise the login error when output back in the login form, leading to a reflected Cross-Site Scripting issue. This issue does not require authentication and can be exploited with the default configuration.
- Affected versions
-
max 3.8.2.
- Status
-
vulnerable