Input validation vulnerability in SAML Single Sign On – SSO Login [16-16.0.8)

The SSO Login plugin for WordPress is not secure in versions up to 20.0.7 because it does not check where users are being redirected. This means that an attacker can make authenticated users go to a different website than what they expected. The same vulnerability affects the Premium Edition (versions before 12.1.0) and Standard Edition (versions before 16.0.8) of the plugin.

Detected in:

SAML Single Sign On – SSO Login fixed vulnerable versions: >= 20 <= 20.0.7
SAML Single Sign On – SSO Login Standard fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.