← WordPress Vulnerabilities
WordPress security by component

Frontegg SAML SSO

Frontegg SAML SSO (frontegg-saml-sso) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 9.8.

Plugin slug: frontegg-saml-sso

CVE-2026-75800: Frontegg SAML SSO accepts unsigned or untrusted assertions

Frontegg SAML SSO through 1.0.1 establishes WordPress sessions without verifying the signature or issuer of SAML authentication responses. An unauthenticated attacker can forge an assertion to log in as any existing user, including an administrator, or create an arbitrary account. The authoritative export does not name the assertion endpoint or mapped identity fields.

PublishedSep 12, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for frontegg-saml-sso
Safe version
Sep 12, 2026 CVE-2026-75800
Frontegg SAML SSO accepts unsigned or untrusted assertions
Frontegg SAML SSO through 1.0.1 establishes WordPress sessions without verifying the signature or issuer of SAML authentication responses. An unauthenticated attacker can forge an assertion to log in as any existing user, including an administrator, or create an arbitrary account. The authoritative export does not name the assertion endpoint or mapped identity fields.
See mitigation notes
CVE9.8
NVDPending