CVE-2026-15981
SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter
Description
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's openssl_verify(), causing an error return value of -1 to be evaluated as truthy and therefore treated as a successful signature verification. This makes it possible for unauthenticated attackers to log in as any existing WordPress user, including administrators, by submitting a crafted SAMLResponse containing an attacker-controlled NameID and a deliberately malformed signature value that triggers an OpenSSL processing error — bypassing verification entirely and resulting in wp_set_auth_cookie() being called for the targeted account.
In plain language
AI Act nowIf you use the WordPress plugin SAML Single Sign On – SSO Login version 5.4.4 or older, attackers can log in as any WordPress user (including admins) remotely without needing a password—this is an urgent risk and you should act now.
Unauthenticated authentication bypass in SAML Single Sign On – SSO Login via a crafted SAMLResponse: the plugin mishandles a signature-maximum/verification failure condition and treats it as a successful login, allowing remote takeover of any existing WordPress account.
What to do now
- Check whether you run WordPress and the plugin "SAML Single Sign On – SSO Login" and note its installed version.
- If the plugin version is 5.4.4 or earlier (or you’re unsure), treat the site as vulnerable immediately and restrict exposure (see Step 3).
- Disable the SSO login feature in WordPress (or disable the plugin) until it can be verified as fixed.
- Contact your plugin vendor/IT support to confirm whether a fixed version exists for CVE-2026-15981; if no fix is available, plan for an urgent replacement or permanent disablement.
- Review WordPress user accounts for unexpected new admin users and check recent admin login activity, then rotate passwords for any accounts that may have been accessed.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- WordPress Websites Targeted via MiniOrange Plugin Vulnerabilitiesen-us·SecurityWeek· Exploited WordPress auth-bypass
- Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Accessen·The Hacker News· Exploited miniOrange SAML 2.0 Single Sign On plugin auth-bypass
- Hackers target WordPress sites in miniOrange auth bypass attacksen-us·BleepingComputer· Exploited miniOrange SAML SSO Plugin auth-bypass
- One slug, seven editions: the miniOrange SAML SSO bug that let anyone log in as your WordPress adminen·Patchstack· Exploited miniOrange auth-bypass
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-15981 and every CVE in our database. Create a free account — no credit card required.
Create Free Account