PT-2026-95920 · WordPress · Saml Sp Single Sign On
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAML Single Sign On WordPress plugin versions prior to 6.0.0
Description
The plugin fails to honor the configured criterion for linking an incoming single sign-on identity to a WordPress account. It always resolves the identity by login name regardless of the site configuration. This allows an attacker who can influence the identity provider to assert a specific login name to authenticate as any account, including those with administrator privileges, without proving ownership of the account.
Recommendations
Update the SAML Single Sign On WordPress plugin to version 6.0.0 or later.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Saml Sp Single Sign On