WordPress Plugin Vulnerabilities

SAML Single Sign On 4.8.85 - 5.4.6 - Unauthenticated Administrator Account Takeover via SAML Trust Anchor Overwrite

Description

The plugin does not verify the signature of a SAML response before storing the certificate it carries, and offers an administrator a one-click control that promotes that stored certificate to the site's trusted signing certificate, allowing unauthenticated attackers to have a certificate of their own trusted and then authenticate as any user, including an administrator.

Proof of Concept

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
Suhayb Ahmed
Submitter
Suhayb Ahmed
Verified
Yes

Timeline

Publicly Published
2026-08-17 (about 3 days ago)
Added
2026-08-17 (about 2 days ago)
Last Updated
2026-08-18 (about 1 day ago)

Other