CVE-2026-2418: Unknown Login With Salesforce
Critical severity, CVSS 9.1. EPSS: 0.3% chance of exploitation in the next 30 days.
The Login with Salesforce WordPress plugin through 1.0.2 does not validate that users are allowed to login through Salesforce, allowing unauthenticated users to be authenticated as any user (such as admin) by simply knowing the email
Affected products
- Unknown Login With Salesforce: up to and including 1.0.2
Published 2026-03-05. Last modified 2026-06-17.