WordPress Plugin Vulnerabilities

Login with Salesforce <= 1.0.2 - Unauthenticated Authentication Bypass

Description

The plugin does not validate that users are allowed to login through Salesforce, allowing unauthenticated users to be authenticated as any user (such as admin) by simply knowing the email

Proof of Concept

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
Khaled Alenazi (Nxploited)
Submitter
Khaled Alenazi (Nxploited)
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-02-12 (about 1 month ago)
Added
2026-02-12 (about 1 month ago)
Last Updated
2026-02-12 (about 1 month ago)

Other