← WordPress Vulnerabilities
WordPress security by component

SAML Single Sign On – SSO Login

SAML Single Sign On – SSO Login is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Jul 23, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: miniorange-saml-20-single-sign-on

CVE-2026-15981: miniOrange SAML signature errors permit administrator login

SAML Single Sign On – SSO Login through 5.4.4 accepts a crafted public SAMLResponse because Mo_SAML_Utilities::mo_saml_validate_signature() treats the tri-state openssl_verify() result as a boolean. A deliberately malformed signature can make OpenSSL return -1, which the vulnerable code accepts as success; the attacker-controlled NameID then reaches mo_saml_login_user() and wp_set_auth_cookie(), allowing login as an existing user, including an administrator.

PublishedJul 23, 2026
Known safe version5.4.5
Safe version
Jul 23, 2026 CVE-2026-15981
miniOrange SAML signature errors permit administrator login
SAML Single Sign On – SSO Login through 5.4.4 accepts a crafted public SAMLResponse because Mo_SAML_Utilities::mo_saml_validate_signature() treats the tri-state openssl_verify() result as a boolean. A deliberately malformed signature can make OpenSSL return -1, which the vulnerable code accepts as success; the attacker-controlled NameID then reaches mo_saml_login_user() and wp_set_auth_cookie(), allowing login as an existing user, including an administrator.
5.4.5
CVE9.8
NVDPending
Jul 16, 2026 CVE-2026-15013
SAML Single Sign On – SSO Login: Privilege escalation or authentication bypass
SAML Single Sign On – SSO Login is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 5.4.3.
> 5.4.3
CVE9.8
NVDPending
Dec 13, 2024 CVE-2023-41873
SAML SP Single Sign On: A security weakness
SAML SP Single Sign On is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Feb 17, 2020 CVE-2020-6850
Miniorange Saml 20 Single Sign On: Cross-site scripting
Miniorange Saml 20 Single Sign On is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1