WordPress Plugin Vulnerabilities

OneLogin SAML SSO < 3.6.0 - Authentication Bypass / Admin Account Takeover

Description

The plugin does not correctly validate the signature of SAML assertions, due to a vulnerability in the bundled xmlseclibs library (CVE-2025-66475), allowing unauthenticated attackers to forge an assertion and log in as an administrator. The issue was supposed to be fixed in 3.5.0 however the plugin did not bump the version and stayed at 3.4.0

Proof of Concept

Affects Plugins

Fixed in 3.6.0

References

Classification

Miscellaneous

Submitter
Erwan LR (WPScan)
Verified
Yes

Timeline

Publicly Published
2026-07-01 (about 1 month ago)
Added
2026-07-01 (about 1 month ago)
Last Updated
2026-08-18 (about 5 days ago)

Other