HivePress Authentication

HivePress Authentication has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of September 2026. Their average CVSS score is 7.5, and the most serious one scores 7.5 out of 10. Severity breakdown: 0 critical and 1 high.

The most common weakness is Improper Authentication, behind 1 of the records (100%).

The one issue recorded for HivePress Authentication has a vendor fix available, so running the current release closes it.

All of these findings were reported by Mutantgun. HivePress Authentication is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSHigh
7.5/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all HivePress Authentication vulnerabilities before they are exploited.

Highest severity on recordCVSS 7.5CVE-2026-18056

HivePress Authentication <= 1.1.4 - Unauthenticated Authentication Bypass via 'access_token' Parameter to Facebook Authenticator

Read the full analysis

Vulnerability Records

1 records
Plugin Profile
Latestv1.1.5

HivePress Authentication

HivePress

Author

HivePress

5.0(1)
100/100
Last Updated
2026-08-24 (13d ago)
Active Installs
1,000+
Downloads
31,737
Requires WP
5.0+
Requires PHP
7.4+
Tested up to
WP 7.1
Created
2019-10-16 (7y ago)

HivePress Authentication is an extension for HivePress plugin. It allows users to sign in via third-party services. Please note that this extension is no longer in active development. If you need similar functionality, please consider this one as a replacement. Demo | Docs | Support

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C