PT-2026-23220 · Salesforce+1 · Salesforce+1

Khaled Alenazi

·

Published

2026-03-05

·

Updated

2026-03-06

·

CVE-2026-2418

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Login with Salesforce WordPress plugin version 1.0.2
Description The Login with Salesforce WordPress plugin does not properly validate user access permissions when logging in through Salesforce. This allows unauthenticated users to authenticate as any user, including administrators, simply by knowing their email address.
Recommendations Update the Login with Salesforce WordPress plugin to a version beyond 1.0.2.

Exploit

Fix

Related Identifiers

CVE-2026-2418

Affected Products

Login With Salesforce
Salesforce