Impact
This vulnerability allows an unauthenticated attacker to exploit the WordPress SAML SP Single Sign On plugin (versions 5.4.3 and older) to gain elevated privileges. By abusing flawed authorization controls (CWE‑266), the attacker may obtain administrator rights over the WordPress site, enabling full control over content, users, and settings.
Affected Systems
The affected product is the miniOrange WordPress SAML SP Single Sign On plugin for WordPress, with all versions up to and including 5.4.3 identified as vulnerable.
Risk and Exploitability
The CVSS score of 8.1 classifies this flaw as high severity. The EPSS score is not available, so the current exploitation probability cannot be quantified, and the vulnerability is not listed in CISA KEV. Based on the description, the attack vector is an unauthenticated request to the plugin’s SAML endpoint, which can be exploited over the network without prior authentication, potentially allowing a threat actor to elevate privileges to an administrator level.
OpenCVE Enrichment