HivePress Authentication <= 1.1.4 - Unauthenticated Authentication Bypass via 'access_token' Parameter to Facebook Authenticator
highThe HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is due to the authenticate_user function's Facebook authenticator resolving third-party identity by forwarding the attacker-supplied access_token to t...
- CVSS:
- 7.5 (Wordfence)
- Affected:
- up to 1.1.4
- Fixed in:
- 1.1.5
- Disclosed:
- Sep 5, 2026