Vulnerability Description
The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML response before storing the certificate it carries, and offers an administrator a one-click control that promotes that stored certificate to the site's trusted signing certificate, allowing unauthenticated attackers to have a certificate of their own trusted and then authenticate as any user, including an administrator.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-19842?
CVE-2026-19842 is a vulnerability with a CVSS score of 8.8 (HIGH). The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML response before storing the certificate it carries, and offers an administrator a one-click control that ...
How severe is CVE-2026-19842?
CVE-2026-19842 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-19842?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.