
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2418 is an unauthenticated authentication bypass vulnerability in the Login with Salesforce WordPress plugin through version 1.0.2. The plugin fails to validate whether users are permitted to authenticate via Salesforce, allowing any unauthenticated attacker who knows a target user's email address to log in as that user — including administrators. It was publicly disclosed on February 12, 2026, and was discovered by researcher Khaled Alenazi (Nxploited). The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) per WPScan, and 9.1 (Critical) per NVD (WPScan, Red Hat CVE).
The root cause is improper authentication (CWE-287 / OWASP A2: Broken Authentication and Session Management): the plugin processes a Salesforce SAML login callback without verifying that the authenticating user has a valid, authorized Salesforce session. The vulnerable endpoint (/?option=readsamllogin) accepts a POST request with STATUS=SUCCESS and a Base64-encoded NameID (email address); if the email matches an existing WordPress user, the plugin calls wp_set_auth_cookie() and grants a fully authenticated session — no Salesforce credentials or token are required. Exploitation is trivially easy when the mo_saml_customer_token option is empty, which is the default configuration (WPScan).
A successful exploit grants the attacker a fully authenticated WordPress session as any existing user whose email is known, including site administrators. This results in high confidentiality impact (access to all site data, user credentials, private content) and high integrity impact (ability to modify site content, install malicious plugins/themes, create backdoor accounts, or pivot to the underlying server). Availability is not directly impacted by the authentication bypass itself, but a compromised admin account could be used to take the site fully offline or deploy ransomware (WPScan, Red Hat CVE).
A public proof-of-concept (PoC) curl command is included in the WPScan advisory, making exploitation trivial for any attacker who knows a target user's email address. As of the time of reporting, there is no confirmed evidence of active in-the-wild exploitation, and the CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.022% (0.000220), indicating a currently low but non-zero probability of exploitation in the near term. No specific threat actor attribution has been reported (WPScan, Red Hat CVE).
login-with-salesforce plugin (version ≤ 1.0.2) via passive scanning tools (e.g., WPScan, Shodan, or Google dorks such as inurl:"login-with-salesforce"). Enumerate target user email addresses through public sources, WordPress author pages, or contact forms.mo_saml_customer_token WordPress option is empty (the default), which is required for the bypass to work without additional token validation.curl -i -X POST "http://example.com/?option=readsamllogin" \
-d "STATUS=SUCCESS" \
-d "NameID=$(echo -n 'admin@targetsite.com' | base64)"wp_set_auth_cookie() for the matched user and returns a Set-Cookie header with a valid WordPress authentication cookie./wp-admin/ as the impersonated user, achieving full administrative control (WPScan)./?option=readsamllogin from external or unknown IP addresses, especially with STATUS=SUCCESS and a Base64-encoded NameID parameter in the body; absence of a preceding legitimate Salesforce OAuth/SAML redirect flow before the callback./?option=readsamllogin not preceded by a Salesforce IdP redirect; authentication events for admin or privileged accounts from unfamiliar IP addresses or geographic locations.As of the disclosure date, no patched version of the Login with Salesforce plugin is available (the plugin has no known fix). The recommended immediate action is to deactivate and remove the plugin until a patched version is released. Site administrators should also audit WordPress user logs for suspicious authentication events, rotate credentials for all privileged accounts, and consider restricting access to the WordPress admin interface via IP allowlisting or a Web Application Firewall (WAF) rule blocking POST requests to /?option=readsamllogin. Additionally, enabling multi-factor authentication (MFA) for WordPress admin accounts via a separate plugin can reduce the risk of account takeover (WPScan).
The vulnerability was discovered and responsibly disclosed by independent researcher Khaled Alenazi (Nxploited), who also provided the PoC. WPScan verified and published the advisory. No significant vendor statement, mainstream media coverage, or notable community debate has been identified beyond the initial WPScan publication (WPScan).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."