The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML response before storing the certificate it carries, and offers an administrator a one-click control that promotes that stored certificate to the site's trusted signing certificate, allowing unauthenticated attackers to have a certificate of their own trusted and then authenticate as any user, including an administrator.
Metrics
Affected Vendors & Products
References
History
Wed, 19 Aug 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML response before storing the certificate it carries, and offers an administrator a one-click control that promotes that stored certificate to the site's trusted signing certificate, allowing unauthenticated attackers to have a certificate of their own trusted and then authenticate as any user, including an administrator. | |
| Title | SAML Single Sign On 4.8.85 - 5.4.6 - Unauthenticated Administrator Account Takeover via SAML Trust Anchor Overwrite | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-08-19T06:00:21.841Z
Reserved: 2026-08-14T08:01:39.582Z
Link: CVE-2026-19842
No data.
Status : Received
Published: 2026-08-19T06:17:40.613
Modified: 2026-08-19T06:17:40.613
Link: CVE-2026-19842
No data.
OpenCVE Enrichment
No data.