A security flaw has been found in the WordPress SAML Single Sign On (SSO Login) plugin, affecting all versions up to and including 5.4.4. The issue stems from a coding error in how the plugin verifies the legitimacy of SAML login requests, the system that lets users sign into your site using an external account (like a work or school login).
This error allows unauthenticated attackers to completely bypass the plugin’s login security. Even without an existing account on your WordPress site, a bad actor can submit a specially crafted, malicious login request that tricks the plugin into treating it as valid. This lets the attacker log in as any existing user on your site, including administrators who have full control over your website, its content, and user accounts.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15981