CVE-2026-2418: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-2418 is an unauthenticated authentication bypass vulnerability in the Login with Salesforce WordPress plugin through version 1.0.2. The plugin fails to validate whether users are permitted to authenticate via Salesforce, allowing any unauthenticated attacker who knows a target user's email address to log in as that user — including administrators. It was publicly disclosed on February 12, 2026, and was discovered by researcher Khaled Alenazi (Nxploited). The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) per WPScan, and 9.1 (Critical) per NVD (WPScan, Red Hat CVE).

Technical details

The root cause is improper authentication (CWE-287 / OWASP A2: Broken Authentication and Session Management): the plugin processes a Salesforce SAML login callback without verifying that the authenticating user has a valid, authorized Salesforce session. The vulnerable endpoint (/?option=readsamllogin) accepts a POST request with STATUS=SUCCESS and a Base64-encoded NameID (email address); if the email matches an existing WordPress user, the plugin calls wp_set_auth_cookie() and grants a fully authenticated session — no Salesforce credentials or token are required. Exploitation is trivially easy when the mo_saml_customer_token option is empty, which is the default configuration (WPScan).

Impact

A successful exploit grants the attacker a fully authenticated WordPress session as any existing user whose email is known, including site administrators. This results in high confidentiality impact (access to all site data, user credentials, private content) and high integrity impact (ability to modify site content, install malicious plugins/themes, create backdoor accounts, or pivot to the underlying server). Availability is not directly impacted by the authentication bypass itself, but a compromised admin account could be used to take the site fully offline or deploy ransomware (WPScan, Red Hat CVE).

Exploitability

A public proof-of-concept (PoC) curl command is included in the WPScan advisory, making exploitation trivial for any attacker who knows a target user's email address. As of the time of reporting, there is no confirmed evidence of active in-the-wild exploitation, and the CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.022% (0.000220), indicating a currently low but non-zero probability of exploitation in the near term. No specific threat actor attribution has been reported (WPScan, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the login-with-salesforce plugin (version ≤ 1.0.2) via passive scanning tools (e.g., WPScan, Shodan, or Google dorks such as inurl:"login-with-salesforce"). Enumerate target user email addresses through public sources, WordPress author pages, or contact forms.
  2. Verify default configuration: Confirm that the mo_saml_customer_token WordPress option is empty (the default), which is required for the bypass to work without additional token validation.
  3. Craft the malicious POST request: Base64-encode the target user's email address and send a POST request to the vulnerable endpoint:
curl -i -X POST "http://example.com/?option=readsamllogin" \
  -d "STATUS=SUCCESS" \
  -d "NameID=$(echo -n 'admin@targetsite.com' | base64)"
  1. Capture the authentication cookie: The plugin calls wp_set_auth_cookie() for the matched user and returns a Set-Cookie header with a valid WordPress authentication cookie.
  2. Access the WordPress admin panel: Use the captured cookie in subsequent requests to access /wp-admin/ as the impersonated user, achieving full administrative control (WPScan).

Indicators of compromise

  • Network: Unexpected POST requests to /?option=readsamllogin from external or unknown IP addresses, especially with STATUS=SUCCESS and a Base64-encoded NameID parameter in the body; absence of a preceding legitimate Salesforce OAuth/SAML redirect flow before the callback.
  • Logs: WordPress access logs showing POST requests to /?option=readsamllogin not preceded by a Salesforce IdP redirect; authentication events for admin or privileged accounts from unfamiliar IP addresses or geographic locations.
  • WordPress Activity: New administrator accounts created shortly after suspicious login events; installation of unfamiliar plugins or themes; changes to site settings, user roles, or file permissions by accounts that did not perform a standard login.
  • File System: Presence of web shells or backdoor PHP files in the WordPress uploads directory or plugin folders following a suspicious authentication event.

Mitigation and workarounds

As of the disclosure date, no patched version of the Login with Salesforce plugin is available (the plugin has no known fix). The recommended immediate action is to deactivate and remove the plugin until a patched version is released. Site administrators should also audit WordPress user logs for suspicious authentication events, rotate credentials for all privileged accounts, and consider restricting access to the WordPress admin interface via IP allowlisting or a Web Application Firewall (WAF) rule blocking POST requests to /?option=readsamllogin. Additionally, enabling multi-factor authentication (MFA) for WordPress admin accounts via a separate plugin can reduce the risk of account takeover (WPScan).

Community reactions

The vulnerability was discovered and responsibly disclosed by independent researcher Khaled Alenazi (Nxploited), who also provided the PoC. WPScan verified and published the advisory. No significant vendor statement, mainstream media coverage, or notable community debate has been identified beyond the initial WPScan publication (WPScan).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management