WordPress Plugin Vulnerabilities

SAML Single Sign On 4.8.85 - 5.4.6 - Unauthenticated Administrator Account Takeover via SAML Trust Anchor Overwrite

Description

The plugin does not verify the signature of a SAML response before storing the certificate it carries, and offers an administrator a one-click control that promotes that stored certificate to the site's trusted signing certificate, allowing unauthenticated attackers to have a certificate of their own trusted and then authenticate as any user, including an administrator.

Proof of Concept

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
Suhayb Ahmed (cyboltx)
Submitter
Suhayb Ahmed (cyboltx)
Verified
Yes

Timeline

Publicly Published
2026-08-17 (about 24 days ago)
Added
2026-08-17 (about 23 days ago)
Last Updated
2026-08-31 (about 9 days ago)

Other