Input validation vulnerability in SAML Single Sign On – SSO Login 4.9.20

The SAML Single Sign On – SAML SSO Login plugin for WordPress has a security issue that could let unauthenticated attackers inject malicious web scripts into pages that execute. This vulnerability is present in versions up to and including 4.9.20 and is caused by the use of the add_query_arg function on the URL without appropriate escaping. In order to exploit this issue, an attacker would have to convince a user to click on a malicious link.

Detected in:

SAML Single Sign On – SSO Login fixed vulnerable versions: >= * <= 4.9.20
SAML Single Sign On – SSO Login Standard fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.