ZeroHour

CVE-2026-75800

niche

Unauthenticated SAML Signature Bypass in Frontegg SAML SSO WordPress Plugin

CVSS 3.1
9.8 critical
EPSS
Published
()
Modified
AI analysis

The Frontegg SAML SSO WordPress plugin through version 1.0.1 does not verify the cryptographic signature or issuer of SAML authentication responses before establishing a login session (CWE-287, improper authentication). An unauthenticated remote attacker can craft a forged SAML response for the target site and submit it to the plugin's SSO endpoint, which accepts it without any validation. This lets the attacker log in as any existing user — including administrators — and create arbitrary new accounts, resulting in complete site takeover (CVSS 3.1: 9.8, critical). Any WordPress site running this plugin at version 1.0.1 or earlier with SAML SSO in use is affected. No public proof of concept is known, the issue is not on the CISA KEV list, and no exploitation in the wild has been reported to date.

What to do: Upgrade to a patched release above 1.0.1 as soon as one is available (monitor WPScan and the WordPress.org plugin page); until then, disable or remove the plugin and use an alternative SAML SSO solution, or restrict access to the plugin's SAML assertion endpoint at the firewall/WAF. Inspect user lists and authentication logs for unexpected accounts or admin logins, delete any rogue accounts, and reset credentials for all privileged users.

Affected
Frontegg SAML SSO (WordPress plugin)All versions through 1.0.1
Estimated exposure
nichelikely on the order of hundreds to a few thousand sites at most (no published active-install count) — This is a niche enterprise SSO integration with no large published active-install count on WordPress.org, so exposure is plausibly limited to Frontegg customers who installed the plugin on WordPress sites.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log in as any user, including administrators, as well as to create arbitrary accounts.

Ecosystems
WordPress
Weakness
CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.