{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/saml-single-sign-on--sso-login-plugin--5.4.4/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-15981"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SAML Single Sign On – SSO Login plugin (\u003c= 5.4.4)"],"_cs_severities":["critical"],"_cs_tags":["authentication-bypass","wordpress","web-vulnerability","cve-2026-15981"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe SAML Single Sign On - SSO Login plugin for WordPress, in all versions up to and including 5.4.4, is affected by a critical authentication bypass vulnerability, identified as CVE-2026-15981. This flaw, discovered and published on July 23, 2026, stems from a logical error within the \u003ccode\u003emo_saml_validate_signature()\u003c/code\u003e function. Specifically, a loose boolean check incorrectly interprets an OpenSSL \u003ccode\u003eopenssl_verify()\u003c/code\u003e error return value of \u003ccode\u003e-1\u003c/code\u003e as a successful signature verification. This design flaw enables unauthenticated attackers to craft specific SAMLResponse messages. By including an attacker-controlled NameID for a target user and a specially malformed signature designed to trigger the OpenSSL error, adversaries can completely bypass the authentication process, allowing them to log in as any existing WordPress user, including those with administrative privileges.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target WordPress instance running the vulnerable SAML Single Sign On - SSO Login plugin (versions 5.4.4 or earlier).\u003c/li\u003e\n\u003cli\u003eThe attacker obtains or infers a valid username on the targeted WordPress site, such as an administrator account.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious SAMLResponse XML payload, including the identified target user's NameID.\u003c/li\u003e\n\u003cli\u003eThe crafted payload deliberately includes a malformed XML digital signature value designed to cause PHP's \u003ccode\u003eopenssl_verify()\u003c/code\u003e function to return \u003ccode\u003e-1\u003c/code\u003e (an error state) during signature validation.\u003c/li\u003e\n\u003cli\u003eThe attacker sends this crafted SAMLResponse within an HTTP POST request to the WordPress site's SAML authentication endpoint.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003emo_saml_validate_signature()\u003c/code\u003e function within the plugin attempts to verify the signature.\u003c/li\u003e\n\u003cli\u003eDue to the loose boolean comparison, the function evaluates the \u003ccode\u003e-1\u003c/code\u003e error return from \u003ccode\u003eopenssl_verify()\u003c/code\u003e as a 'truthy' value, mistakenly treating it as a successful signature verification.\u003c/li\u003e\n\u003cli\u003eThe plugin proceeds to call \u003ccode\u003ewp_set_auth_cookie()\u003c/code\u003e for the user specified in the NameID, granting the attacker an authenticated session for the targeted WordPress account.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eA successful exploitation of CVE-2026-15981 allows an unauthenticated attacker to gain full administrative access to affected WordPress sites. This can lead to comprehensive compromise of the website, including data exfiltration, defacement, injection of malicious code, or further lateral movement within the hosting environment. Organizations utilizing the vulnerable plugin face severe risks of unauthorized access to sensitive information, disruption of services, and significant reputational damage. The critical CVSS score of 9.8 reflects the ease of exploitation and the high impact of this vulnerability.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-15981 immediately by updating the SAML Single Sign On - SSO Login plugin for WordPress to a version greater than 5.4.4.\u003c/li\u003e\n\u003cli\u003eMonitor webserver access logs for unusual POST requests directed at SAML authentication endpoints, especially those that might indicate attempts to bypass authentication.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-23T21:18:41Z","date_published":"2026-07-23T21:18:41Z","id":"https://feed.craftedsignal.io/briefs/2026-07-wordpress-saml-auth-bypass/","summary":"A critical authentication bypass vulnerability, CVE-2026-15981, affects the SAML Single Sign On - SSO Login plugin for WordPress (versions up to and including 5.4.4), allowing unauthenticated attackers to log in as any existing user, including administrators, by crafting a malformed SAMLResponse that misleads the plugin's signature validation logic.","title":"WordPress SAML Single Sign On Plugin Authentication Bypass (CVE-2026-15981)","url":"https://feed.craftedsignal.io/briefs/2026-07-wordpress-saml-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - SAML Single Sign on – SSO Login Plugin (\u003c= 5.4.4)","version":"https://jsonfeed.org/version/1.1"}