There is a security vulnerability in the SAML Single Sign On (SSO) Login plugin for WordPress, a tool many sites use to let users log in with existing external accounts (such as work or school credentials) instead of a separate password for your site. All versions of this plugin up to and including version 5.4.4 are affected by this flaw.
The vulnerability allows unauthenticated attackers to completely bypass the plugin's login security checks. By submitting a specially crafted fake login request, an attacker can gain access to any existing user account on the affected site, including administrator accounts that have full control over site content, settings, and user data.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15981