A security flaw has been identified in the popular WordPress plugin SAML Single Sign On (SSO Login), a tool that lets users log into WordPress sites using credentials from other services they already use. All versions of the plugin up to and including version 5.4.4 are affected by this vulnerability.
The flaw stems from a coding error that causes the plugin to incorrectly mark failed security signature checks as successful. This allows unauthenticated attackers to completely bypass login security, and log in as any existing user on your WordPress site, including site administrators, by submitting a specially crafted fake login request. No valid account credentials or prior access to your site are required to carry out this attack.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15981