THREAT OPS › Threat News › [NVD] CVE-2026-18056 (HIGH 7.5) — The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is due to the authenticate_user function's Facebook authenticator resolving third-party identity by forwarding
[NVD] CVE-2026-18056 (HIGH 7.5) — The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is due to the authenticate_user function's Facebook authenticator resolving third-party identity by forwarding
CVE-2026-18056 CVSS: 7.5 HIGH Published: 2026-09-06T03:17:16.467
The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is due to the authenticate_user function's Facebook authenticator resolving third-party identity by forwarding the attacker-supplied access_token to the Facebook Gr
Indicators of compromise
- CVE-2026-18056cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18056