CVSS
No CVSS.
T
he Login with Salesforce WordPress plugin through 1.0.2 does not validate that users are allowed to login through Salesforce, allowing unauthenticated users to be authenticated as any user (such as admin) by simply knowing the email
References
Configurations
No configuration.
History
05 Mar 2026, 06:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-05 06:16
Updated : 2026-03-05 19:38
NVD link : CVE-2026-2418
Mitre link : CVE-2026-2418
CVE.ORG link : CVE-2026-2418
JSON object : View
Products Affected
No product.
CWE
No CWE.