Логотип exploitDog
bind:CVE-2026-2418
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-2418

Количество 2

Количество 2

nvd логотип

CVE-2026-2418

21 день назад

The Login with Salesforce WordPress plugin through 1.0.2 does not validate that users are allowed to login through Salesforce, allowing unauthenticated users to be authenticated as any user (such as admin) by simply knowing the email

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-22f9-qcfx-q3w3

21 день назад

The Login with Salesforce WordPress plugin through 1.0.2 does not validate that users are allowed to login through Salesforce, allowing unauthenticated users to be authenticated as any user (such as admin) by simply knowing the email

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-2418

The Login with Salesforce WordPress plugin through 1.0.2 does not validate that users are allowed to login through Salesforce, allowing unauthenticated users to be authenticated as any user (such as admin) by simply knowing the email

CVSS3: 9.1
0%
Низкий
21 день назад
github логотип
GHSA-22f9-qcfx-q3w3

The Login with Salesforce WordPress plugin through 1.0.2 does not validate that users are allowed to login through Salesforce, allowing unauthenticated users to be authenticated as any user (such as admin) by simply knowing the email

CVSS3: 9.1
0%
Низкий
21 день назад

Уязвимостей на страницу