CVE-2026-75800
published 2026-09-12CVE-2026-75800: The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session…
PriorityP261critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.63%
47.9th percentile
The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log in as any user, including administrators, as well as to create arbitrary accounts.
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log i
ghsa_unreviewed·2026-09-12
CVE-2026-75800 [CRITICAL] CWE-287 The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log i
The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log in as any user, including administrators, as well as to create arbitrary accounts.
VulDB
Frontegg SAML SSO Plugin up to 1.0.1 on WordPress improper authentication (EUVD-2026-76816)
vuldb·2026-09-12·CVSS 9.8
CVE-2026-75800 [CRITICAL] Frontegg SAML SSO Plugin up to 1.0.1 on WordPress improper authentication (EUVD-2026-76816)
A vulnerability described as critical has been identified in Frontegg SAML SSO Plugin up to 1.0.1 on WordPress. Affected by this issue is some unknown functionality. Executing a manipulation can lead to improper authentication.
This vulnerability is registered as CVE-2026-75800. It is possible to launch the attack remotely. No exploit is available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-12
Published