Description
The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for linking an incoming single sign-on identity to a WordPress account, always resolving the identity by login name whatever the site has chosen, which allows an attacker who can have the site's identity provider assert a login name of their choosing to authenticate as any account, including an administrator, without proving ownership of that account.
Published: 2026-09-20
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated privilege escalation via SAML account matching
Action: Patch Now
AI Analysis

Impact

The SAML Single Sign On WordPress plugin prior to version 6.0.0 contains a logic flaw that ignores the administrator’s configured account‑matching rule and always associates an incoming SAML assertion with a WordPress account solely based on the login name supplied by the identity provider. Consequently, an attacker who can cause the identity provider to assert a chosen login name can authenticate as that account without needing the user’s credentials. This flaw provides an avenue for unauthenticated privilege escalation, allowing an attacker to assume the role of any site user, including administrators.

Affected Systems

All WordPress sites that employ the SAML Single Sign On plugin in any version older than 6.0.0 are affected. The issue resides entirely in the plugin logic and is independent of the underlying WordPress core version, so any site running a vulnerable plugin installation requires remediation.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.1 and an EPSS score of < 1%, indicating high severity and a low exploitation probability; it is not listed in CISA KEV. The impact is substantial: an attacker capable of supplying forged SAML assertions can impersonate any account on the site, including privileged administrators, without proof of ownership. The attack is achievable by controlling or compromising the identity provider used by the site, or by authorizing a malicious provider to send assertions. Given the potential to fully compromise site administration, the risk can be considered high.

Generated by OpenCVE AI on September 20, 2026 at 17:37 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the SAML Single Sign On plugin to version 6.0.0 or later to enforce the correct account linking rules.
  • Configure the plugin to use the intended account‑matching criterion and disable fallback to login‑name matching.
  • Limit the set of trusted identity providers and reject SAML assertions that originate from untrusted sources.

Generated by OpenCVE AI on September 20, 2026 at 17:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions saml Single Sign On
Vendors & Products Wordpress-extensions
Wordpress-extensions saml Single Sign On

Sun, 20 Sep 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-285
CWE-639

Sun, 20 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
CWE-285
CWE-639

Sun, 20 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for linking an incoming single sign-on identity to a WordPress account, always resolving the identity by login name whatever the site has chosen, which allows an attacker who can have the site's identity provider assert a login name of their choosing to authenticate as any account, including an administrator, without proving ownership of that account.
Title SAML Single Sign On < 6.0.0 - Unauthenticated Privilege Escalation via Account Matching
References

Subscriptions

Wordpress-extensions Saml Single Sign On
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-20T13:49:00.235Z

Reserved: 2026-08-31T08:27:11.846Z

Link: CVE-2026-82842

cve-icon Vulnrichment

Updated: 2026-09-20T13:48:43.359Z

cve-icon NVD

Status : Deferred

Published: 2026-09-20T07:16:50.093

Modified: 2026-09-21T13:34:57.127

Link: CVE-2026-82842

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:48:46Z

Weaknesses
  • CWE-269

    Improper Privilege Management