cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forminiorange-saml-20-single-sign-on miniorange-saml-20-single-sign-on

Direction: ascending
Jun 07, 2024

SAML Single Sign On – SSO Login # CVE-2020-6850

CVE, Research URL

CVE-2020-6850

Date
Feb 17, 2020
Research Description
Utilities.php in the miniorange-saml-20-single-sign-on plugin before 4.8.84 for WordPress allows XSS via a crafted SAML XML Response to wp-login.php. This is related to the SAMLResponse and RelayState variables, and the Destination parameter of the samlp:Response XML element.
Affected versions
max 4.8.84.
Status
vulnerable

SAML Single Sign On – SSO Login # CVE-2022-4496

CVE, Research URL

CVE-2022-4496

Date
Jan 31, 2023
Research Description
The SAML SSO Standard WordPress plugin version 16.0.0 before 16.0.8, SAML SSO Premium WordPress plugin version 12.0.0 before 12.1.0 and SAML SSO Premium Multisite WordPress plugin version 20.0.0 before 20.0.7 does not validate that the redirect parameter to its SSO login endpoint points to an internal site URL, making it vulnerable to an Open Redirect issue when the user is already logged in.
Affected versions
max 4.9.32.
Status
vulnerable

SAML Single Sign On – SSO Login # CVE-2019-12346

CVE, Research URL

CVE-2019-12346

Date
Jun 25, 2019
Research Description
In the miniOrange SAML SP Single Sign On plugin before 4.8.73 for WordPress, the SAML Login Endpoint is vulnerable to XSS via a specially crafted SAMLResponse XML post.
Affected versions
max 4.8.73.
Status
vulnerable
Jun 10, 2024

SAML Single Sign On – SSO Login # CVE-2023-41873

CVE, Research URL

CVE-2023-41873

Date
Dec 13, 2024
Research Description
Missing Authorization vulnerability in miniOrange SAML SP Single Sign On allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SAML SP Single Sign On: from n/a through 5.0.4.
Affected versions
max 5.0.5.
Status
vulnerable
Jun 16, 2026

SAML Single Sign On – SSO Login # 7f92698e-3e18-4236-b7eb-a1215275e853

Date
-
Research Description
SAML Single Sign On – SSO Login [miniorange-saml-20-single-sign-on] < 4.8.74 SAML SP SSO &lt;= 4.8.70 - Multiple Cross-Site Request Forgery (CSRF) The SAML Single Sign On &ndash; SSO Login WordPress plugin was affected by a Multiple Cross-Site Request Forgery (CSRF) security vulnerability.
Affected versions
max 4.8.74.
Status
vulnerable

SAML Single Sign On – SSO Login # 7f6d85eb3f4ac07cbd1874787a296ed25f0b4e37

Date
Jun 07, 2022
Research Description
SAML Single Sign On – SSO Login [miniorange-saml-20-single-sign-on] < 4.9.21 WordPress SAML Single Sign On – SAML SSO Login plugin <= 4.9.20 - Reflected Cross-Site Scripting (XSS) vulnerability Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress SAML Single Sign On – SAML SSO Login plugin (versions <= 4.9.20). Update the WordPress SAML Single Sign On – SAML SSO Login plugin to the latest available version (at least 4.9.21).
Affected versions
max 4.9.21.
Status
vulnerable

SAML Single Sign On – SSO Login # 4ecbb8fd57e13ce7fb7146abf3cddc01e41aba59

Date
May 20, 2019
Research Description
SAML Single Sign On – SSO Login [miniorange-saml-20-single-sign-on] < 4.8.76 SAML Single Sign On – SAML SSO Login <= 4.8.75 - Cross-Site Request Forgery The SAML Single Sign On plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.8.75. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to gain otherwise restricted access to administrative actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 4.8.76.
Status
vulnerable

SAML Single Sign On – SSO Login # 31719ed91775c0a28f0392cff0dc482f80895ac0

Date
Jun 27, 2019
Research Description
SAML Single Sign On – SSO Login [miniorange-saml-20-single-sign-on] < 4.8.73 WordPress SAML SP Single Sign On plugin <= 4.8.72 - Cross-Site Scripting (XSS) vulnerability Cross-Site Scripting (XSS) vulnerability found by ZEROAUTH in WordPress SAML SP Single Sign On plugin (versions <= 4.8.72).
Affected versions
max 4.8.73.
Status
vulnerable

SAML Single Sign On – SSO Login # cc45319e99b421896e2ccf543ab2dd31227ae288

Date
Jun 06, 2022
Research Description
SAML Single Sign On – SSO Login [miniorange-saml-20-single-sign-on] < 4.9.21 SAML Single Sign On – SAML SSO Login <= 4.9.20 - Reflected Cross-Site Scripting The SAML Single Sign On – SAML SSO Login plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 4.9.20. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Affected versions
max 4.9.21.
Status
vulnerable
Jul 17, 2026

SAML Single Sign On – SSO Login # CVE-2026-15013

CVE, Research URL

CVE-2026-15013

Date
Jul 16, 2026
Research Description
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3. The vulnerability exists because `Mo_SAML_Utilities::mo_saml_cast_key()` reads the `SignatureMethod` Algorithm attribute directly from the attacker-controlled `SAMLResponse` parameter rather than enforcing the locally configured algorithm, causing the plugin to recast the IdP's RSA public key as an HMAC-SHA1 shared secret and validate the forged signature against it. This makes it possible for unauthenticated attackers to forge a SAML assertion targeting any WordPress account — including administrators — obtain valid WordPress authentication cookies, and achieve full administrator-level account takeover.
Affected versions
max 5.4.4.
Status
vulnerable
Jul 29, 2026

SAML Single Sign On – SSO Login # CVE-2026-15981

CVE, Research URL

CVE-2026-15981

Date
Jul 24, 2026
Research Description
The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's openssl_verify(), causing an error return value of -1 to be evaluated as truthy and therefore treated as a successful signature verification. This makes it possible for unauthenticated attackers to log in as any existing WordPress user, including administrators, by submitting a crafted SAMLResponse containing an attacker-controlled NameID and a deliberately malformed signature value that triggers an OpenSSL processing error — bypassing verification entirely and resulting in wp_set_auth_cookie() being called for the targeted account.
Affected versions
max 5.4.5.
Status
vulnerable
Aug 15, 2026

SAML Single Sign On – SSO Login # CVE-2026-61979

CVE, Research URL

CVE-2026-61979

Date
Aug 13, 2026
Research Description
Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions.
Affected versions
max 5.4.4.
Status
vulnerable
Aug 21, 2026

SAML Single Sign On – SSO Login # CVE-2026-19842

CVE, Research URL

CVE-2026-19842

Date
Aug 19, 2026
Research Description
The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML response before storing the certificate it carries, and offers an administrator a one-click control that promotes that stored certificate to the site's trusted signing certificate, allowing unauthenticated attackers to have a certificate of their own trusted and then authenticate as any user, including an administrator.
Affected versions
max 5.4.7.
Status
vulnerable
Sep 22, 2026

SAML Single Sign On – SSO Login # CVE-2026-82842

CVE, Research URL

CVE-2026-82842

Date
Sep 20, 2026
Research Description
The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for linking an incoming single sign-on identity to a WordPress account, always resolving the identity by login name whatever the site has chosen, which allows an attacker who can have the site's identity provider assert a login name of their choosing to authenticate as any account, including an administrator, without proving ownership of that account.
Affected versions
max 6.0.0.
Status
vulnerable