miniOrange SAML Single Sign On
- <= 5.4.3
A vulnerability allowing authentication bypass has been identified in the SAML Single Sign On – SSO Login plugin for WordPress, affecting all versions through 5.4.3. This vulnerability arises from the plugin's improper handling of the 'SignatureMethod' Algorithm attribute within the 'SAMLResponse' parameter. Instead of applying the user's configured algorithm, the plugin allows attackers to dictate the algorithm, leading to the misinterpretation of the Identity Provider's RSA public key as a shared secret. Exploiting this flaw, attackers can forge SAML assertions, target any WordPress user, including administrators, and gain access to their accounts by stealing authentication cookies.
Successful exploitation allows unauthenticated attackers to bypass authentication, forge SAML assertions, and take over any WordPress account, including those with administrative privileges.
Users are advised to update the SAML Single Sign On – SSO Login plugin to version 5.4.4 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.