A security vulnerability has been identified in the SAML Single Sign On (SSO Login) plugin for WordPress, impacting all versions up to and including 5.4.4. The flaw is an authentication bypass bug that lets unauthenticated attackers skip the plugin's normal login verification process entirely. This means someone without a valid account for your site can log in as any existing WordPress user, including administrators, by submitting a specially crafted fake login request. No legitimate account credentials are required to exploit this issue.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15981