VYPR

HivePress Authentication

by WordPress

CVEs (1)

  • CVE-2026-18056Sep 6, 2026
    risk 0.00cvss epss

    The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is due to the authenticate_user function's Facebook authenticator resolving third-party identity by…