Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-22f9-qcfx-q3w3

Опубликовано: 05 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

The Login with Salesforce WordPress plugin through 1.0.2 does not validate that users are allowed to login through Salesforce, allowing unauthenticated users to be authenticated as any user (such as admin) by simply knowing the email

The Login with Salesforce WordPress plugin through 1.0.2 does not validate that users are allowed to login through Salesforce, allowing unauthenticated users to be authenticated as any user (such as admin) by simply knowing the email

EPSS

Процентиль: 22%
0.00071
Низкий

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.1
nvd
21 день назад

The Login with Salesforce WordPress plugin through 1.0.2 does not validate that users are allowed to login through Salesforce, allowing unauthenticated users to be authenticated as any user (such as admin) by simply knowing the email

EPSS

Процентиль: 22%
0.00071
Низкий

9.1 Critical

CVSS3