THREAT OPS › Threat News › [NVD] CVE-2026-75807 (HIGH 7.5) — The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 5.4.6. This is due to the mo_saml_login_validate() ACS handler persisting the X.509 certificate extracted from an incoming SAMLResponse into the mo_sa
[NVD] CVE-2026-75807 (HIGH 7.5) — The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 5.4.6. This is due to the mo_saml_login_validate() ACS handler persisting the X.509 certificate extracted from an incoming SAMLResponse into the mo_sa
CVE-2026-75807 CVSS: 7.5 HIGH Published: 2026-08-29T18:16:36.313
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 5.4.6. This is due to the mo_saml_login_validate() ACS handler persisting the X.509 certificate extracted from an incoming SAMLResponse into the mo_saml_required_certificate option before the signature-va
Indicators of compromise
- CVE-2026-75807cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-75807