Authentication Bypass Vulnerability in SAML Single Sign On Plugin for WordPress
CVE-2026-75807

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
29 August 2026

What is CVE-2026-75807?

The SAML Single Sign On – SSO Login plugin for WordPress is susceptible to an authentication bypass flaw. In versions up to 5.4.6, the mo_saml_login_validate() handler improperly handles the X.509 certificate from incoming SAML responses. Specifically, it persists the certificate into the mo_saml_required_certificate option prior to validating the signature. This flaw may permit unauthorized attackers to replace the plugin's stored Identity Provider (IdP) signing certificate with a malicious one, enabling them to create forged SAML assertions. Consequently, attackers could potentially gain privileged access to WordPress accounts, including those belonging to administrators. Note that the exploitation of this vulnerability contingent upon the administrator executing a repair following a specific error message during configuration testing.

Affected Version(s)

SAML Single Sign On – SSO Login 0 <= 5.4.6

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tanishq Shah
Thatchapol Booranatanit (AliceZz)
.