cbcvebase.

Cyberlord92 Saml Single Sign On Sso Login vulnerabilities

3 known vulnerabilities affecting cyberlord92/saml_single_sign_on_sso_login.

Total CVEs
3
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL2HIGH1

Vulnerabilities

Page 1 of 1
CVE-2026-15981P1CRITICALCVSS 9.8ExploitedPoC≤ 5.4.42026-07-23
CVE-2026-15981 [CRITICAL] CWE-287 CVE-2026-15981: The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in a The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's openssl_verify(), causing an error return value of -1 to be evaluated a
nvd
CVE-2026-15013P2CRITICALCVSS 9.8PoC≤ 5.4.32026-07-16
CVE-2026-15013 [CRITICAL] CWE-347 CVE-2026-15013: The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3. The vulnerability exists because `Mo_SAML_Utilities::mo_saml_cast_key()` reads the `SignatureMethod` Algorithm attribute directly from the attacker-controlled `SAMLRespon
nvd
CVE-2026-75807P3HIGHCVSS 7.5≤ 5.4.62026-08-29
CVE-2026-75807 [HIGH] CWE-287 CVE-2026-75807: The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in v The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 5.4.6. This is due to the mo_saml_login_validate() ACS handler persisting the X.509 certificate extracted from an incoming SAMLResponse into the mo_saml_required_certificate option before the signature-validation verdict is
nvd
Cyberlord92 Saml Single Sign On Sso Login vulnerabilities | cvebase