Executive brief
The Frontegg SAML SSO WordPress plugin, used to authenticate users via SAML-based single sign-on, fails to validate the signature and issuer of SAML authentication responses. This allows attackers without credentials to impersonate any user—including site administrators—or create arbitrary accounts, gaining complete control over a WordPress installation.
Technical details
The vulnerability is an authentication bypass (CWE-287) in SAML response handling. The plugin accepts SAML responses without cryptographic signature verification or issuer validation, allowing unauthenticated attackers to craft forged SAML assertions that authenticate as arbitrary users. The attack requires network access to the WordPress site but no prior authentication or user interaction; exploitation results in privilege escalation and account takeover. No known patch is available at the time of advisory publication.
Affected products
- Frontegg SAML SSO through 1.0.1
Timeline
- 2026-09-10: disclosed
- 2026-09-12: advisory