Shibboleth WordPress Plugin Authentication Bypass Vulnerability Allowing Unauthenticated Administrator Account Creation

Vulnerability

A vulnerability in the Shibboleth WordPress plugin, affecting versions prior to 2.5.4, allows for unauthenticated administrator account creation through identity header spoofing. When the HTTP header identity mode is enabled without an anti-spoofing key, the plugin fails to properly verify identity headers, treating them as authenticated sessions. This issue can be exploited by an unauthenticated attacker on deployments that do not strip untrusted client headers before they reach the application. The exploitation requires the non-default HTTP header attribute mode, an empty or absent spoof key, and automatic account creation enabled, with the default administrator role mapping.

Impact

Exploitation of this vulnerability allows for unauthenticated users to create and log in as new administrators on the WordPress site.

Added: Jul 15, 2026, 7:06 AM
Updated: Jul 15, 2026, 7:06 AM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
5.0
exploitability
7.2
remediation
7.7
relevance
9.4
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.