PT-2026-78307 · WordPress · Saml Sp Single Sign On
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAML Single Sign On versions prior to 5.4.7
Description
The plugin fails to verify the signature of a SAML response before storing the included certificate. An administrator can then promote this stored certificate to the site's trusted signing certificate via a one-click control. This allows unauthenticated attackers to establish trust for their own certificate and authenticate as any user, including those with administrator privileges.
Recommendations
Update to version 5.4.7 or later.
Exploit
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Saml Sp Single Sign On