CVE-2026-15981
cyberlord92 · SAML Single Sign On – SSO Login
The SAML Single Sign On plugin for WordPress contains an authentication bypass flaw that allows unauthenticated users to gain access to any account, including administrative accounts.
Executive summary
A critical authentication bypass vulnerability in the SAML Single Sign On plugin for WordPress allows unauthenticated attackers to hijack administrative sessions.
Vulnerability
The plugin incorrectly validates signature results from the OpenSSL library, where an error state is erroneously treated as a successful verification, allowing unauthenticated attackers to bypass security checks entirely.
Business impact
This vulnerability allows full account takeover, including administrative access, which can lead to complete site compromise, data theft, and the installation of malicious backdoors. The 9.8 CVSS score reflects the ease of exploitation and the high impact on confidentiality, integrity, and availability.
Remediation
Immediate Action: Update the SAML Single Sign On – SSO Login plugin to version 5.4.5 or later immediately.
Proactive Monitoring: Review WordPress user login logs for anomalous activity or logins from unrecognized IP addresses, particularly those involving administrative accounts.
Compensating Controls: Disable the plugin if an immediate update cannot be performed and utilize alternative secure authentication methods until the patch is applied.
Exploitation status
Public Exploit Available: unknown
Analyst recommendation
This vulnerability represents a significant security risk for any WordPress site utilizing this plugin for SSO. Immediate patching to version 5.4.5 is mandatory to prevent unauthorized administrative access and potential full system compromise.