WordPress security by component
Frontegg SAML SSO
Frontegg SAML SSO (frontegg-saml-sso) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 9.8.
Plugin slug:
frontegg-saml-ssoLatest vulnerability
CVE-2026-75800: Frontegg SAML SSO accepts unsigned or untrusted assertions
Frontegg SAML SSO through 1.0.1 establishes WordPress sessions without verifying the signature or issuer of SAML authentication responses. An unauthenticated attacker can forge an assertion to log in as any existing user, including an administrator, or create an arbitrary account. The authoritative export does not name the assertion endpoint or mapped identity fields.
| Safe version |
|
||
|---|---|---|---|
| Sep 12, 2026 |
CVE-2026-75800
Frontegg SAML SSO accepts unsigned or untrusted assertions
Frontegg SAML SSO through 1.0.1 establishes WordPress sessions without verifying the signature or issuer of SAML authentication responses. An unauthenticated attacker can forge an assertion to log in as any existing user, including an administrator, or create an arbitrary account. The authoritative export does not name the assertion endpoint or mapped identity fields.
|
See mitigation notes |
CVE9.8
NVDPending
|