Shibboleth
cpe:2.3:a:shibboleth_project:shibboleth:*:*:*:*:wordpress:*:*
- < 2.5.4
A vulnerability in the Shibboleth WordPress plugin, affecting versions prior to 2.5.4, allows for unauthenticated administrator account creation through identity header spoofing. When the HTTP header identity mode is enabled without an anti-spoofing key, the plugin fails to properly verify identity headers, treating them as authenticated sessions. This issue can be exploited by an unauthenticated attacker on deployments that do not strip untrusted client headers before they reach the application. The exploitation requires the non-default HTTP header attribute mode, an empty or absent spoof key, and automatic account creation enabled, with the default administrator role mapping.
Exploitation of this vulnerability allows for unauthenticated users to create and log in as new administrators on the WordPress site.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.