Shibboleth

Shibboleth has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2016 and 2026; all 2 are fixed as of September 2026. Their average CVSS score is 8.0, and the most serious one scores 9.8 out of 10. Severity breakdown: 1 critical and 0 high.

The most common weakness is Cross-Site Scripting, behind 1 of the records (50%). Other recurring categories include Missing Authorization.

Every one of the 2 issues recorded for Shibboleth has a vendor fix available, so running the current release closes all known holes.

All of these findings were reported by Khaled Alenazi (Nxploited). Shibboleth is installed on roughly 3,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSHigh
8.0/ 10
Patch Coverage100%
Open

0

Fixed

2

Get automatic notifications for all Shibboleth vulnerabilities before they are exploited.

Highest severity on recordCVSS 9.8CVE-2026-12281

Shibboleth <= 2.5.3 - Unauthenticated Administrator Account Creation

Read the full analysis

Vulnerability Records

2 records
Shibboleth banner
Latestv2.5.4
4.3(7)
86/100
Last Updated
2026-06-22 (3mo ago)
Active Installs
3,000+
Downloads
65,499
Requires WP
4.3+
Requires PHP
5.6+
Tested up to
WP 7.0.4
Created
2008-11-01 (18y ago)

This plugin is designed to support integrating your WordPress site into your existing identity management infrastructure using a Shibboleth Service Provider. WordPress can be configured so that all standard login requests will be sent to your configured Shibboleth Identity Provider or Discovery Service. Upon successful authentication, a new WordPress account will be automatically provisioned for the user if one does not already exist. User attributes (username, first name, last name, display name, nickname, and email address) can be synchronized with your enterprise’s system of record each time the user logs into WordPress. Finally, the user’s role within WordPress can be automatically set (and continually updated) based on any attribute Shibboleth provides. For example, you may decide to give users with an eduPersonAffiliation value of faculty the WordPress role of editor, while the eduPersonAffiliation value of student maps to the WordPress role contributor. Or you may choose to limit access to WordPress altogether using a special eduPersonEntitlement value. Contribute on GitHub This plugin is actively maintained by michaelryanmcneill and the WordPress community, using GitHub. Contributions are welcome, via pull request, on GitHub. Issues can be submitted on the issue tracker.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C