CVE-2026-19842
8.8WordPress · SAML Single Sign On
The SAML Single Sign On WordPress plugin contains an improper authentication vulnerability that may allow unauthorized access to the application.
Executive summary
An improper authentication vulnerability in the SAML Single Sign On WordPress plugin could permit unauthorized access, creating a significant security risk.
Vulnerability
This is an Improper Authentication (CWE-287) vulnerability that potentially allows unauthenticated attackers to bypass security controls within the SAML authentication flow.
Business impact
A vulnerability in the authentication mechanism of a Single Sign On (SSO) plugin can result in full account takeover or unauthorized access to sensitive administrative functions. With a CVSS score of 8.8, this flaw constitutes a major risk to the overall security posture and data integrity of the WordPress site.
Remediation
Immediate Action: Update the SAML Single Sign On plugin to version 5.4.7 or later to resolve the authentication flaw.
Proactive Monitoring: Review authentication logs for anomalous login attempts or successful logins from unexpected sources that coincide with the use of the SSO plugin.
Compensating Controls: If immediate patching is not feasible, consider disabling SSO functionality and reverting to standard WordPress authentication methods until the update is applied.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
The severity of this authentication flaw necessitates immediate remediation. Administrators should verify the current version of the SAML Single Sign On plugin and apply the specified update to version 5.4.7 or higher to ensure the integrity of the authentication process.