A security flaw has been found in the SAML Single Sign On (SSO Login) plugin for WordPress, impacting all versions up to and including 5.4.4.
The issue lies in how the plugin checks if incoming SSO login requests are authentic. A bug in its signature verification process causes malformed, fake login requests to be incorrectly marked as valid. This allows unauthenticated attackers (people with no existing account on your site) to submit a specially crafted fake login request to access any existing WordPress user account on your site, including administrator accounts.
If your site uses this plugin for single sign-on, a successful attack would let an attacker take full control of your WordPress site, including modifying content, accessing private user data, or making harmful changes to your site's settings.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15981