Authentication vulnerability in OneLogin SAML SSO 2.1.6

The OneLogin SAML-SSO plugin for WordPress is a security tool that can be used to help protect websites from unauthorized access. However, a vulnerability was discovered in versions up to and including 2.1.5 which could allow unauthenticated attackers to create new accounts, including administrator accounts, without needing to authenticate. To do this, they must correctly guess the role name, username, or email address of an existing administrator.

Detected in:

OneLogin SAML SSO fixed vulnerable versions: >= * < 2.1.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.