The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML response before storing the certificate it carries, and offers an administrator a one-click control that promotes that stored certificate to the site's trusted signing certificate, allowing unauthenticated attackers to have a certificate of their own trusted and then authenticate as any user, including an administrator.
History

Wed, 19 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 19 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML response before storing the certificate it carries, and offers an administrator a one-click control that promotes that stored certificate to the site's trusted signing certificate, allowing unauthenticated attackers to have a certificate of their own trusted and then authenticate as any user, including an administrator.
Title SAML Single Sign On 4.8.85 - 5.4.6 - Unauthenticated Administrator Account Takeover via SAML Trust Anchor Overwrite
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2026-08-19T06:00:21.841Z

Updated: 2026-08-19T16:41:23.609Z

Reserved: 2026-08-14T08:01:39.582Z

Link: CVE-2026-19842

cve-icon Vulnrichment

Updated: 2026-08-19T15:56:27.469Z

cve-icon NVD

Status : Received

Published: 2026-08-19T06:17:40.613

Modified: 2026-08-19T17:18:38.787

Link: CVE-2026-19842

cve-icon Redhat

No data.