Executive brief
The SAML Single Sign On WordPress plugin improperly verifies identity linkage during single sign-on authentication, ignoring configured matching criteria and always matching by login name. An attacker with control over an identity provider can assert any login name and gain unauthorized access to any WordPress account, including administrator accounts, without credential verification.
Technical details
The plugin fails to honour the configured criterion for linking incoming SSO identities to WordPress accounts, always resolving by login name regardless of configuration. An attacker controlling the identity provider can assert arbitrary login names to authenticate as any user without ownership verification. This is an authentication bypass allowing unauthenticated privilege escalation when the attacker has IdP control.
Affected products
- miniorange SAML Single Sign On before 6.0.0
Timeline
- 2026-09-18: disclosed
- 2026-09-20: patched: Fixed in version 6.0.0