Login with Salesforce <= 1.0.2 - Authentication Bypass
criticalThe Login with Salesforce plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.0.2. This makes it possible for unauthenticated attackers to log in as any user, including administrators.
- CVSS:
- 9.8
- Affected:
- up to 1.0.2
- Fix:
- No patched version reported
- Disclosed:
- Feb 12, 2026