Authentication Bypass in HivePress Authentication Plugin for WordPress
CVE-2026-18056
What is CVE-2026-18056?
The HivePress Authentication plugin for WordPress contains a vulnerability that allows unauthorized users to bypass authentication using the access_token parameter. In all versions up to and including 1.1.4, the plugin's authenticate_user function improperly validates identity by forwarding the attacker-supplied access_token to the Facebook Graph API, without checking the application ID or audience. This lax validation means that attackers could potentially gain access as any existing user, including those with admin privileges, if they have access to the victim's Facebook access token. Exploiting this vulnerability requires the attacker to procure a valid token associated with the target’s Facebook account.
Affected Version(s)
HivePress Authentication 0 <= 1.1.4