CVE-2025-13910 | axton WP-WebAuthn Plugin up to 1.3.4 on WordPress AJAX Endpoint wwa_auth cross site scripting
A vulnerability described as problematic has been identified in axton WP-WebAuthn Plugin up to 1.3.4 on WordPress. The affected element is the function wwa_auth of the component AJAX Endpoint. The manipulation results in cross site scripting.
This vulnerability is reported as CVE-2025-13910. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.