Impact
The SAML Single Sign On – SSO Login plugin for WordPress contains an authentication bypass flaw. The plugin accepts the SignatureMethod algorithm declared in the attacker‑controlled SAMLResponse instead of the algorithm configured by the site administrator. This allows an attacker to reinterpret a legitimate RSA public key as an HMAC‑SHA1 shared secret, validate a forged signature, and obtain a valid WordPress authentication cookie. The result is a full administrator‑level takeover of the target site.
Affected Systems
The vulnerability affects the WordPress plugin "SAML Single Sign On – SSO Login" from cyberlord92. All releases through version 5.4.3 are impacted. Users should verify the exact version of the plugin in use and determine whether it falls within the affected range.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, while the EPSS score of 0.01504 demonstrates a very low but non‑zero exploitation probability in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is that an unauthenticated attacker can send a crafted SAMLResponse to the site, bypass authentication without valid credentials, and obtain administrative privileges. Such an exploit requires only network access to the site and does not rely on prior compromise or credentials.
OpenCVE Enrichment