CVE-2026-15981 (matched: wordpress)

  • Friday, 24th July, 2026
  • 10:04am

A security flaw has been found in the WordPress plugin "SAML Single Sign On – SSO Login", a tool used to let users log in to WordPress sites via single sign-on services. All versions of the plugin up to and including 5.4.4 are affected by this issue.

The flaw stems from a coding error that causes the plugin to incorrectly mark failed login verification checks as successful. This allows unauthenticated attackers to completely bypass normal login security, and log in as any existing user on your WordPress site, including administrators, by submitting a specially crafted fake login request.

Because this access bypass does not require a valid password or any prior account credentials, an attacker who exploits this flaw could gain the same permissions as the user they impersonate. If they target an administrator account, they could make changes to your site, access private data, or take full control of your WordPress installation.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15981

« Back