SAML Single Sign On – SSO Login

MiniOrange's SAML Single Sign On plugin allows WordPress sites to integrate with a wide range of identity providers, including Azure AD, Keycloak, Okta, Salesforce, and more. The plugin provides SAML authentication for WordPress, allowing users to log in to the site using their existing credentials from their identity provider. A video tutorial is available to guide users through the configuration process.

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Access violation vulnerability in SAML Single Sign On – SSO Login Standard 5.0.4

    Fixed

    The WordPress SAML SP Single Sign On plugin has a security vulnerability in versions up to 5.0.4. This vulnerability allows someone with a subscriber-level access or higher to dismiss the welcome tou...

    Read More
  • Input validation vulnerability in SAML Single Sign On – SSO Login 4.9.20

    Fixed

    The SAML Single Sign On – SAML SSO Login plugin for WordPress has a security issue that could let unauthenticated attackers inject malicious web scripts into pages that execute. This vulnerability ...

    Read More
  • Input validation vulnerability in SAML Single Sign On – SSO Login 4.8.73

    Fixed

    The miniOrange SAML SP Single Sign On plugin for WordPress

    Read More
  • Input validation vulnerability in SAML Single Sign On – SSO Login [16-16.0.8)

    Fixed

    The SSO Login plugin for WordPress is not secure in versions up to 20.0.7 because it does not check where users are being redirected. This means that an attacker can make authenticated users go to a d...

    Read More
  • Input validation vulnerability in SAML Single Sign On – SSO Login 4.8.83

    Fixed

    The miniorange-saml-20-single-sign-on plugin for WordPress (version 4.8.84 and earlier) has a security vulnerability that allows Cross-Site Scripting (XSS) when a certain type of crafted SAML XML Resp...

    Read More
  • Input validation vulnerability in SAML Single Sign On – SSO Login 4.8.75

    Fixed

    The SAML Single Sign On plugin for WordPress is vulnerable to a type of attack called Cross-Site Request Forgery. This means that in versions up to and including 4.8.75, attackers can gain access to ...

    Read More