Summary
CVE-2026-15981 is a critical authentication bypass vulnerability in the SAML Single Sign On – SSO Login WordPress plugin (by cyberlord92/miniOrange), affecting all versions up to and including 5.4.4. The flaw allows unauthenticated remote attackers to log in as any existing WordPress user — including administrators — by submitting a crafted SAMLResponse that exploits a loose return-value check in the plugin’s signature verification function. The vulnerability carries a CVSS v3.1 score of 9.8 (Critical).
Technical details
- Root cause: The
mo_saml_validate_signature()function performs a loose boolean check on the tri-state integer returned by PHP’sopenssl_verify(). Whenopenssl_verify()returns-1(indicating an error condition), the code incorrectly evaluates it as truthy — treating an OpenSSL processing error as a successful signature verification. - Trigger conditions: An attacker submits a crafted
SAMLResponseto the plugin’s SAML assertion consumer endpoint containing an attacker-controlledNameIDand a deliberately malformed signature value designed to trigger an internal OpenSSL error. - Attack vector: Network-based, requiring no authentication, no user interaction, and no prior account on the target system. Exploitation requires SAML SSO to be configured on the target WordPress site.
- Impact: Because signature verification is bypassed entirely, the plugin proceeds to call
wp_set_auth_cookie()for the attacker-specified account, granting an authenticated session as any targeted WordPress user — including administrators — resulting in full, unauthenticated administrator account takeover.
Affected software
- SAML Single Sign On – SSO Login (WordPress plugin, slug:
miniorange-saml-20-single-sign-on) — all versions up to and including 5.4.4
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector String:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CWE: CWE-287 – Improper Authentication
Mitigation and recommended actions
- Immediate action: Update the SAML Single Sign On – SSO Login plugin to version 5.4.5 or later. The WordPress.org plugin changelog for version 5.4.5 confirms: "Bugfix: Fixed unauthorised access issue in SAML SSO."
- If immediate patching is not possible: Temporarily disable the SAML Single Sign On – SSO Login plugin until the update can be applied. Restricting network access to the WordPress SAML assertion consumer endpoint at the perimeter or WAF level can reduce exposure, but is not a substitute for patching.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

