CVE-2026-18056 | HivePress Authentication Plugin up to 1.1.4 on WordPress Facebook Authenticator authenticate_user access_token improper authentication

SecurityVulns

A vulnerability was found in HivePress Authentication Plugin up to 1.1.4 on WordPress. It has been classified as critical. This vulnerability affects the function authenticate_user of the component Facebook Authenticator. Performing a manipulation of the argument access_token results in improper authentication.

This vulnerability is cataloged as CVE-2026-18056. It is possible to initiate the attack remotely. There is no exploit available.VulDB Recent EntriesRead More