A security flaw has been discovered in the SAML Single Sign On (SSO) Login plugin for WordPress, a popular tool that lets users sign into WordPress sites using their existing work, school, or other organizational accounts instead of separate passwords for each site. The vulnerability affects all versions of the plugin up to and including version 5.4.4.
Due to a coding error in the plugin, attackers do not need any valid login credentials to access your site. By sending a specially crafted fake login request, an unauthenticated attacker can trick the system into treating them as any existing user on your site, including administrators who have full control over site content, private data, and core site settings.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15981