OpenID Connect Generic Client
OpenID Connect Generic Client has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2021 and 2025; all 2 are fixed as of September 2026. Their average CVSS score is 6.3, and the most serious one scores 6.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 2 of the records (100%).
Every one of the 2 issues recorded for OpenID Connect Generic Client has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. OpenID Connect Generic Client is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.0.
CVE-2025-13730OpenID Connect Generic Client <= 3.10.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Read the full analysisVulnerability Records
OpenID Connect Generic Client
Author
Jonathan Daggerhart
This plugin allows to authenticate users against OpenID Connect OAuth2 API with Authorization Code Flow. Once installed, it can be configured to automatically authenticate users (SSO), or provide a “Login with OpenID Connect” button on the login form. After consent has been obtained, an existing user is automatically logged into WordPress, while new users are created in WordPress database. Much of the documentation can be found on the Settings > OpenID Connect Generic dashboard page. Please submit issues to the Github repo: https://github.com/oidc-wp/openid-connect-generic
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C