Impact
The SAML Single Sign On WordPress plugin prior to version 6.0.0 contains a logic flaw that ignores the administrator’s configured account‑matching rule and always associates an incoming SAML assertion with a WordPress account solely based on the login name supplied by the identity provider. Consequently, an attacker who can cause the identity provider to assert a chosen login name can authenticate as that account without needing the user’s credentials. This flaw provides an avenue for unauthenticated privilege escalation, allowing an attacker to assume the role of any site user, including administrators.
Affected Systems
All WordPress sites that employ the SAML Single Sign On plugin in any version older than 6.0.0 are affected. The issue resides entirely in the plugin logic and is independent of the underlying WordPress core version, so any site running a vulnerable plugin installation requires remediation.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.1 and an EPSS score of < 1%, indicating high severity and a low exploitation probability; it is not listed in CISA KEV. The impact is substantial: an attacker capable of supplying forged SAML assertions can impersonate any account on the site, including privileged administrators, without proof of ownership. The attack is achievable by controlling or compromising the identity provider used by the site, or by authorizing a malicious provider to send assertions. Given the potential to fully compromise site administration, the risk can be considered high.
OpenCVE Enrichment