Product
The HivePress Authentication plugin for WordPress through version 1.1.4 is vulnerable to authentication bypass via improper validation of Facebook OAuth tokens, allowing unauthenticated attackers to impersonate arbitrary users.