authLdap

authLdap has 2 disclosed vulnerabilities in the WordSec catalog, all reported in 2023; all 2 are fixed as of September 2026. Their average CVSS score is 3.8, and the most serious one scores 4.3 out of 10. 2023 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (50%). Other recurring categories include Cross-Site Scripting.

Every one of the 2 issues recorded for authLdap has a vendor fix available, so running the current release closes all known holes.

All of these findings were reported by Rio Darmawan. authLdap is installed on roughly 4,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSLow
3.8/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all authLdap vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.3CVE-2023-41654

authLdap <= 2.5.8 - Cross-Site Request Forgery

Read the full analysis

Vulnerability Records

2 records
Plugin Profile
Latestv3.1.4
5.0(19)
100/100
Last Updated
2026-07-12 (2mo ago)
Active Installs
4,000+
Downloads
144,256
Requires WP
2.5.0+
Requires PHP
7.4+
Tested up to
WP 7.0.4
Created
2010-08-27 (16y ago)

Use your existing LDAP as authentication-backend for your wordpress! So what are the differences to other WordPress-LDAP-Authentication-Plugins? Flexible: You are totaly free in which LDAP-backend to use. Due to the extensive configuration you can freely decide how to do the authentication of your users. It simply depends on your filters Independent: As soon as a user logs in, it is added/updated to the WordPress’ user-database to allow wordpress to always use the correct data. You only have to administer your users once. Failsafe: Due to the users being created in WordPress’ User-database they can also log in when the LDAP-backend currently is gone. Role-Aware: You can map WordPress’ roles to values of an existing LDAP-attribute. For more Information on the configuration have a look at https://github.com/heiglandreas/authLdap

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C