authLdap
authLdap has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2023; all 2 are fixed as of September 2026. Their average CVSS score is 3.8, and the most serious one scores 4.3 out of 10. 2023 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Cross-Site Scripting.
Every one of the 2 issues recorded for authLdap has a vendor fix available, so running the current release closes all known holes.
All of these findings were reported by Rio Darmawan. authLdap is installed on roughly 4,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2023-41654authLdap <= 2.5.8 - Cross-Site Request Forgery
Read the full analysisVulnerability Records
authLdap
Author
heiglandreas
Use your existing LDAP as authentication-backend for your wordpress! So what are the differences to other WordPress-LDAP-Authentication-Plugins? Flexible: You are totaly free in which LDAP-backend to use. Due to the extensive configuration you can freely decide how to do the authentication of your users. It simply depends on your filters Independent: As soon as a user logs in, it is added/updated to the WordPress’ user-database to allow wordpress to always use the correct data. You only have to administer your users once. Failsafe: Due to the users being created in WordPress’ User-database they can also log in when the LDAP-backend currently is gone. Role-Aware: You can map WordPress’ roles to values of an existing LDAP-attribute. For more Information on the configuration have a look at https://github.com/heiglandreas/authLdap
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C