
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-19842 is an unauthenticated administrator account takeover vulnerability in the SAML Single Sign On WordPress plugin (by miniOrange), classified as an Authentication Bypass (CWE-287). The plugin fails to verify the signature of a SAML response before storing the certificate it carries, and exposes a one-click admin control to promote that stored certificate to the site's trusted signing certificate — enabling unauthenticated attackers to have their own certificate trusted and then authenticate as any user, including administrators. Affected versions span 4.8.85 through 5.4.6; version 5.4.7 contains the fix. The vulnerability was publicly disclosed on August 17, 2026, with the CVE record published on August 19, 2026. WPScan assigned a CVSS score of 8.8 (High) (WPScan, Github Advisory).
The root cause is improper authentication (CWE-287) stemming from a missing SAML response signature verification step. When a SAML response is received, the plugin stores the certificate embedded in the response without first validating that the response was signed by a trusted Identity Provider. An administrator is then presented with a one-click UI control to promote any stored certificate to the site's trusted signing certificate (trust anchor). An unauthenticated attacker can craft a malicious SAML response containing their own self-signed certificate, submit it to the plugin's SAML endpoint, and — once an administrator clicks the promotion control (either through social engineering or if the control is triggered automatically) — the attacker's certificate becomes trusted, allowing them to forge valid SAML assertions and authenticate as any WordPress user. The attack vector is network-accessible and requires no prior authentication (WPScan, Github Advisory).
Successful exploitation results in complete authentication bypass, allowing an attacker to impersonate any WordPress user — including site administrators — without valid credentials. This grants full administrative control over the WordPress site, enabling arbitrary content modification, installation of malicious plugins or backdoors, credential harvesting, and potential lateral movement to connected systems or databases. The confidentiality, integrity, and availability of the entire WordPress installation are at risk (WPScan).
As of the disclosure date (August 19, 2026), there is no public proof-of-concept exploit available; WPScan has indicated the PoC will be published on September 17, 2026 to allow time for users to update. There is no evidence of in-the-wild exploitation at this time. No threat actor attribution has been reported. The EPSS score is currently 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The attack does require an administrator to interact with the one-click certificate promotion control, which slightly raises the exploitation bar, though social engineering could be used to trigger this action (WPScan, Github Advisory).
/wp-content/plugins/miniorange-saml-20-single-sign-on/) or using tools like WPScan.<ds:X509Certificate> element of the <KeyInfo> block. The response does not need to be validly signed by a legitimate IdP./wp-login.php?saml_consumer_endpoint or similar). The plugin stores the embedded certificate without signature verification./wp-login.php?saml_consumer_endpoint) from unknown or external IP addresses, particularly containing large or unusual SAMLResponse parameters./wp-content/plugins/miniorange-saml-20-single-sign-on/; unexpected PHP webshells or backdoor files in the WordPress installation directory.wp_options table (e.g., options prefixed with saml_ or mo_saml_); new administrator accounts created after SAML login events.Upgrade immediately to SAML Single Sign On plugin version 5.4.7 or later, which introduces proper SAML response signature verification before storing or trusting any certificate. As a workaround prior to patching, administrators should disable the SAML Single Sign On plugin entirely if SSO is not critical, or restrict access to the WordPress admin panel (e.g., via IP allowlisting) to reduce the risk of the certificate promotion control being triggered. Additionally, implement controls to limit which administrators can approve certificate changes, and require manual out-of-band verification before trusting new SAML certificates (WPScan, Github Advisory).
The vulnerability was discovered and reported by security researcher Suhayb Ahmed, who also submitted it to WPScan. WPScan has verified the vulnerability and is withholding the full PoC until September 17, 2026, following responsible disclosure practices to give site operators time to update. No major vendor statements beyond the WPScan advisory have been issued at this time, and broader media coverage remains limited given the recent disclosure date (WPScan).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."