PT-2026-23220 · Salesforce+1 · Salesforce+1

Khaled Alenazi

·

Publicado

2026-03-05

·

Atualizado

2026-03-06

·

CVE-2026-2418

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Login with Salesforce WordPress plugin version 1.0.2
Description The Login with Salesforce WordPress plugin does not properly validate user access permissions when logging in through Salesforce. This allows unauthenticated users to authenticate as any user, including administrators, simply by knowing their email address.
Recommendations Update the Login with Salesforce WordPress plugin to a version beyond 1.0.2.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-2418

Produtos afetados

Login With Salesforce
Salesforce