Impact
The vulnerability in the Frontegg SAML SSO WordPress plugin (CWE‑287) allows an attacker to supply a crafted SAMLResponse because the plugin does not verify the response’s signature or issuer. Because the plugin accepts any response, an unauthenticated attacker can establish a session arbitrary accounts. This results in a complete compromise of site accounts and privileged access, posing a critical risk to confidentiality and integrity. While the description does not explicitly state the attack vector, it can be inferred that an attacker can deliver a forged SAMLResponse to the authentication endpoint. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in KEV. This suggests that, although exploitation is theoretically possible, confirmed real‑world attacks are currently rare.
Affected Systems
WordPress sites running the Frontegg SAML SSO plugin version are affected.
Risk and Exploitability
The CVSS score of 9.8 reflects a could lead to full system compromise. The EPSS score of less than 1% and the vulnerability is not currently marked in CISA's KEV catalog mean there are no known active exploits. Nevertheless, the attack requires no credentials and relies solely on a forged SAMLResponse, so it can reach the authentication endpoint.
OpenCVE Enrichment