Shibboleth

Explore Shibboleth vulnerabilities across all versions. Currently tracking 1 known vulnerabilities, including severity, impact, and patch status.

Strategic Overview

Avg CVSSMedium
6.1/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Shibboleth vulnerabilities before they are exploited.

Vulnerability Records

1 records
Showing 1–1 of 1 reports
Shibboleth banner
Latestv2.5.4
4.3(7)
86/100
Last Updated
2026-06-22 (1mo ago)
Active Installs
3,000+
Downloads
64,653
Requires WP
4.3+
Requires PHP
5.6+
Tested up to
WP 7.0.2
Created
2008-11-01 (18y ago)

This plugin is designed to support integrating your WordPress site into your existing identity management infrastructure using a Shibboleth Service Provider. WordPress can be configured so that all standard login requests will be sent to your configured Shibboleth Identity Provider or Discovery Service. Upon successful authentication, a new WordPress account will be automatically provisioned for the user if one does not already exist. User attributes (username, first name, last name, display name, nickname, and email address) can be synchronized with your enterprise’s system of record each time the user logs into WordPress. Finally, the user’s role within WordPress can be automatically set (and continually updated) based on any attribute Shibboleth provides. For example, you may decide to give users with an eduPersonAffiliation value of faculty the WordPress role of editor, while the eduPersonAffiliation value of student maps to the WordPress role contributor. Or you may choose to limit access to WordPress altogether using a special eduPersonEntitlement value. Contribute on GitHub This plugin is actively maintained by michaelryanmcneill and the WordPress community, using GitHub. Contributions are welcome, via pull request, on GitHub. Issues can be submitted on the issue tracker.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C