OneLogin SAML SSO

OneLogin SAML SSO has 5 disclosed vulnerabilities in the WordSec catalog, reported between 2016 and 2021; all 5 are fixed as of September 2026. Their average CVSS score is 7.4, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 3 high. 2016 was the busiest year with 3 disclosures.

The most common weakness is Improper Authentication, behind 1 of the records (20%). Other recurring categories include Improper Verification Of Cryptographic Signature, Open Redirect.

Every one of the 5 issues recorded for OneLogin SAML SSO has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, most of them (2) reported by Jouko Pynnöne. OneLogin SAML SSO is installed on roughly 7,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 5.9.16.

Strategic Overview

Avg CVSSHigh
7.4/ 10
Patch Coverage100%
Open

0

Fixed

5

Get automatic notifications for all OneLogin SAML SSO vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8

OneLogin SAML-SSO Plugin < 2.1.6 - Authentication Bypass

Read the full analysis

Vulnerability Records

5 records
Plugin Profile
Latestv3.6.0

OneLogin SAML SSO

sixtomartin

Author

sixtomartin

4.4(14)
88/100
Last Updated
2026-07-01 (2mo ago)
Active Installs
7,000+
Downloads
212,510
Requires WP
2.1.2+
Requires PHP
0+
Tested up to
WP 5.9.16
Created
2011-01-10 (16y ago)

This SAML plugin eliminates passwords and allows you to authenticate WordPress users (typically editors) against your existing Active Directory or LDAP server as well increase security using YubiKeys or VeriSign VIP Access via OneLogin. OneLogin is pre-integrated with thousands of apps and handles all of your SSO needs in the cloud and behind the firewall. Eliminate passwords in WordPress Allow users to sign into WordPress with their Active Directory or LDAP credentials Give users one-click access from your intranet Increase security using browser PKI certificates or two-factor authentication from Yubico or VeriSign Easily prevent access from former employees and contractors If you used this plugin before 2.2.0 with just-in-time provision active, Read: https://wpvulndb.com/vulnerabilities/8508 To mitigate that bug, place the script at the root of wordpress and execute it (later remove it) https://gist.github.com/pitbulk/a8223c90a3534e9a7d5e0a93009a094f

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C