{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-18056/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:hivepress:authentication:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-18056"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["HivePress Authentication (\u003c= 1.1.4)"],"_cs_severities":["high"],"_cs_tags":["web-application","authentication-bypass","wordpress","cve-2026-18056"],"_cs_type":"advisory","_cs_vendors":["HivePress"],"content_html":"\u003cp\u003eThe HivePress Authentication plugin for WordPress contains an authentication bypass vulnerability (CVE-2026-18056) affecting all versions up to and including 1.1.4. The vulnerability exists within the authenticate_user function, which handles Facebook identity resolution. When an attacker provides an access_token parameter, the plugin forwards this token to the Facebook Graph API. However, the plugin fails to perform necessary validation on the response, specifically omitting /debug_token verification and failing to compare the token's app_id against the locally configured hp_facebook_app_id. Consequently, the plugin trusts the Facebook Graph API response implicitly. An attacker who obtains a valid Facebook access token associated with a target's email address can use that token to authenticate as the target user within the WordPress site. If the target user is an administrator, this grants the attacker full administrative access to the WordPress environment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to hijack any user account within the WordPress installation, including administrator accounts. This leads to full site compromise, potential data exfiltration, and the ability to execute arbitrary code on the web server if administrative privileges are used to upload malicious themes or plugins. This affects any WordPress site utilizing the HivePress Authentication plugin for social login functionality.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the HivePress Authentication plugin to the latest version patched against CVE-2026-18056.\u003c/li\u003e\n\u003cli\u003eIf immediate patching is not possible, disable the Facebook authentication feature within the HivePress plugin settings.\u003c/li\u003e\n\u003cli\u003eAudit WordPress user accounts for suspicious login activity or anomalous administrative actions originating from unknown IP addresses, particularly those associated with successful authentication events recorded by the plugin.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for repeated HTTP requests to the authentication endpoint containing the 'access_token' parameter, which may indicate testing or exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-06T03:35:49Z","date_published":"2026-09-06T03:35:49Z","id":"https://feed.craftedsignal.io/briefs/2026-09-hivepress-auth-bypass/","summary":"The HivePress Authentication plugin for WordPress through version 1.1.4 is vulnerable to authentication bypass via improper validation of Facebook OAuth tokens, allowing unauthenticated attackers to impersonate arbitrary users.","title":"Authentication Bypass in HivePress Authentication Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-hivepress-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-18056","version":"https://jsonfeed.org/version/1.1"}