OneLogin SAML SSO
OneLogin SAML SSO has 5 disclosed vulnerabilities in the WordSec catalog, reported between 2016 and 2021; all 5 are fixed as of September 2026. Their average CVSS score is 7.4, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 3 high. 2016 was the busiest year with 3 disclosures.
The most common weakness is Improper Authentication, behind 1 of the records (20%). Other recurring categories include Improper Verification Of Cryptographic Signature, Open Redirect.
Every one of the 5 issues recorded for OneLogin SAML SSO has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, most of them (2) reported by Jouko Pynnöne. OneLogin SAML SSO is installed on roughly 7,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 5.9.16.
OneLogin SAML-SSO Plugin < 2.1.6 - Authentication Bypass
Read the full analysisVulnerability Records
OneLogin SAML SSO
Author
sixtomartin
This SAML plugin eliminates passwords and allows you to authenticate WordPress users (typically editors) against your existing Active Directory or LDAP server as well increase security using YubiKeys or VeriSign VIP Access via OneLogin. OneLogin is pre-integrated with thousands of apps and handles all of your SSO needs in the cloud and behind the firewall. Eliminate passwords in WordPress Allow users to sign into WordPress with their Active Directory or LDAP credentials Give users one-click access from your intranet Increase security using browser PKI certificates or two-factor authentication from Yubico or VeriSign Easily prevent access from former employees and contractors If you used this plugin before 2.2.0 with just-in-time provision active, Read: https://wpvulndb.com/vulnerabilities/8508 To mitigate that bug, place the script at the root of wordpress and execute it (later remove it) https://gist.github.com/pitbulk/a8223c90a3534e9a7d5e0a93009a094f
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C