CVE-2026-2418

CVSS

No CVSS.

T

he Login with Salesforce WordPress plugin through 1.0.2 does not validate that users are allowed to login through Salesforce, allowing unauthenticated users to be authenticated as any user (such as admin) by simply knowing the email

Configurations

No configuration.

History

05 Mar 2026, 06:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-05 06:16

Updated : 2026-03-05 19:38


NVD link : CVE-2026-2418

Mitre link : CVE-2026-2418

CVE.ORG link : CVE-2026-2418


JSON object : View

Products Affected

No product.

CWE

No CWE.