THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-75807 (HIGH 7.5) — The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 5.4.6. This is due to the mo_saml_login_validate() ACS handler persisting the X.509 certificate extracted from an incoming SAMLResponse into the mo_sa

[NVD] CVE-2026-75807 (HIGH 7.5) — The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 5.4.6. This is due to the mo_saml_login_validate() ACS handler persisting the X.509 certificate extracted from an incoming SAMLResponse into the mo_sa

mednvdPublished 2026-08-29

CVE-2026-75807 CVSS: 7.5 HIGH Published: 2026-08-29T18:16:36.313

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 5.4.6. This is due to the mo_saml_login_validate() ACS handler persisting the X.509 certificate extracted from an incoming SAMLResponse into the mo_saml_required_certificate option before the signature-va

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-75807