Impact
The vulnerability in the Frontegg SAML SSO WordPress plugin allows an attacker to supply a crafted SAMLResponse without the plugin verifying the signature or issuer. Because the plugin accepts any response, an unauthenticated attacker can establish a session as any user, including administrators, or create arbitrary accounts. This results in full compromise of site accounts and privileged access, posing a critical risk to confidentiality, integrity, and availability.
Affected Systems
WordPress sites running the Frontegg SAML SSO plugin version 1.0.1 or earlier are affected.
Risk and Exploitability
The attack vector involves submitting a forged SAMLResponse to the authentication endpoint. No authentication or authorization is required to initiate the process. The EPSS score is < 1% and the vulnerability is not listed in KEV, but the capability to impersonate any user without credentials makes exploitation highly probable once the plugin is live.
OpenCVE Enrichment