A security flaw has been identified in the SAML Single Sign On – SSO Login plugin for WordPress, a tool used to let users log in to websites with a single shared set of credentials. The issue affects all versions of the plugin up to and including 5.4.4.
The vulnerability lets attackers completely bypass the plugin’s login verification process. Unauthenticated third parties can log in as any existing user on a WordPress site running the affected plugin, including administrator accounts, by submitting a specially modified login request. This could allow bad actors to take full control of a site, make unauthorized changes to content or settings, or access sensitive information stored on the site.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15981