THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-18056 (HIGH 7.5) — The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is due to the authenticate_user function's Facebook authenticator resolving third-party identity by forwarding

[NVD] CVE-2026-18056 (HIGH 7.5) — The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is due to the authenticate_user function's Facebook authenticator resolving third-party identity by forwarding

mednvdPublished 2026-09-06

CVE-2026-18056 CVSS: 7.5 HIGH Published: 2026-09-06T03:17:16.467

The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is due to the authenticate_user function's Facebook authenticator resolving third-party identity by forwarding the attacker-supplied access_token to the Facebook Gr

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18056