Impact
The Shibboleth WordPress plugin before 2.5.4 fails to validate identity headers when HTTP header identity mode is enabled without an anti‑spoofing key. As a result, any request carrying the relevant identity headers is treated as an authenticated session. If automatic account creation and the default administrator role mapping are also turned on, an attacker can forge identity headers, create a new administrator account without knowing a password, and obtain full control of the site.
Affected Systems
Installations of the Shibboleth WordPress plugin prior to version 2.5.4, on environments where HTTP header identity mode is enabled, no anti‑spoofing key is configured, automatic account creation is allowed, and untrusted client headers reach the application.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity vulnerability, while the EPSS score of less than 1% suggests a low likelihood of public exploitation at the time of assessment. The issue is not listed in the CISA KEV catalogue. Exploitation requires that the deployment expose untrusted client headers, use the non‑default header attribute mode, and have no anti‑spoofing key. The likely attack vector is a crafted HTTP request to the plugin’s endpoints containing forged identity headers. Under those conditions, an attacker could create a new administrator account and subsequently gain full site access.
OpenCVE Enrichment