OneLogin SAML SSO

OneLogin's SAML plugin for WordPress allows users to authenticate against their existing Active Directory or LDAP server and increase security using YubiKeys or VeriSign VIP Access. The plugin eliminates the need for passwords and allows for one-click access from the intranet. A bug in earlier versions has been fixed with a script that should be executed at the root of WordPress.

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Input validation vulnerability in OneLogin SAML SSO 3.1.2

    Fixed

    The OneLogin SAML SSO plugin for WordPress is vulnerable to a security issue known as open redirection. It affects all versions up to and including 3.1.2. This means that attackers who are not author...

    Read More
  • Authentication vulnerability in OneLogin SAML SSO 2.1.6

    Fixed

    The OneLogin SAML-SSO plugin for WordPress is a security tool that can be used to help protect websites from unauthorized access. However, a vulnerability was discovered in versions up to and includi...

    Read More
  • Denial of Service vulnerability in OneLogin SAML SSO 2.8.0

    Fixed

    The OneLogin SAML SSO for WordPress is a software program which has a security vulnerability in versions up to 2.8.0. Attackers can use a special type of attack called XML External Entity to cause th...

    Read More
  • Authentication vulnerability in OneLogin SAML SSO 2.4.2

    Fixed

    The OneLogin SAML Single Sign On (SSO) plugin for WordPress is potentially vulnerable to a security attack called SAML Signature Wrapping. This vulnerability was caused by the use of an older and les...

    Read More
  • Information leakage vulnerability in OneLogin SAML SSO 2.2.0

    Fixed

    The onelogin-saml-sso plugin for WordPress

    Read More