Authentication Bypass in HivePress Authentication Plugin for WordPress
CVE-2026-18056

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 September 2026

What is CVE-2026-18056?

The HivePress Authentication plugin for WordPress contains a vulnerability that allows unauthorized users to bypass authentication using the access_token parameter. In all versions up to and including 1.1.4, the plugin's authenticate_user function improperly validates identity by forwarding the attacker-supplied access_token to the Facebook Graph API, without checking the application ID or audience. This lax validation means that attackers could potentially gain access as any existing user, including those with admin privileges, if they have access to the victim's Facebook access token. Exploiting this vulnerability requires the attacker to procure a valid token associated with the target’s Facebook account.

Affected Version(s)

HivePress Authentication 0 <= 1.1.4

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mutantgun
.