OpenID Connect Generic Client

OpenID Connect Generic Client has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2021 and 2025; all 2 are fixed as of September 2026. Their average CVSS score is 6.3, and the most serious one scores 6.4 out of 10.

The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).

Every one of the 2 issues recorded for OpenID Connect Generic Client has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. OpenID Connect Generic Client is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.0.

Strategic Overview

Avg CVSSMedium
6.3/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all OpenID Connect Generic Client vulnerabilities before they are exploited.

Highest severity on recordCVSS 6.4CVE-2025-13730

OpenID Connect Generic Client <= 3.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Read the full analysis

Vulnerability Records

2 records
Plugin Profile
Latestv3.11.3

OpenID Connect Generic Client

Jonathan Daggerhart

Author

Jonathan Daggerhart

5.0(20)
100/100
Last Updated
2026-02-13 (7mo ago)
Active Installs
10,000+
Downloads
214,505
Requires WP
5.0+
Requires PHP
7.4+
Tested up to
WP 6.9.0
Created
2018-02-25 (9y ago)

This plugin allows to authenticate users against OpenID Connect OAuth2 API with Authorization Code Flow. Once installed, it can be configured to automatically authenticate users (SSO), or provide a “Login with OpenID Connect” button on the login form. After consent has been obtained, an existing user is automatically logged into WordPress, while new users are created in WordPress database. Much of the documentation can be found on the Settings > OpenID Connect Generic dashboard page. Please submit issues to the Github repo: https://github.com/oidc-wp/openid-connect-generic

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C