Junglewise Threat Intelligence

CVE-2026-12281: Shibboleth WordPress plugin authentication bypass in HTTP header identity mode

CVE-2026-12281 · Severity: info · CVSS 8.1 · Published 2026-07-15

Executive brief

The Shibboleth plugin for WordPress, which provides single sign-on capabilities, contains a security flaw that could allow an unauthorized person to gain full administrative access to a website. By sending specially crafted web requests that mimic identity information, an attacker can bypass the login process and automatically create a new administrator account. This risk is highest for sites that use specific header-based identity settings without a security key and do not have a firewall to block untrusted incoming web headers.

Technical details

The Shibboleth WordPress plugin suffers from an authentication bypass vulnerability (CWE-287) when configured in HTTP header attribute mode. If an anti-spoofing key is absent or empty, the plugin fails to verify the authenticity of identity headers, treating any request containing these headers as a valid authenticated session. An unauthenticated remote attacker can exploit this by providing forged identity headers. If automatic account creation and default administrator role mapping are enabled, the attacker can successfully create and log in as a new administrator. This exploit is possible if the deployment environment does not strip untrusted client headers before they reach the application. The issue is fixed in version 2.5.4.

Affected products

  • Shibboleth Project Shibboleth < 2.5.4

Timeline

  • 2026-06-24: disclosed: Initial public disclosure by WPScan
  • 2026-07-15: advisory: NVD publication date
  • 2026-07-28: other: Scheduled proof of concept release

References