Cloud SAML SSO <= 1.0.19 - Missing Authorization to Unauthenticated Settings Modification via set_organization_settings Action
high
The Cloud SAML SSO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'set_organization_settings' action of the csso_handle_actions() function in all versions up to, and including, 1.0.19. The handler reads client-supplied POST parameters for organization se...
- CVSS:
- 8.2
- Affected:
- up to 1.0.19
- Fixed in:
- 1.0.20
- Disclosed:
- Sep 5, 2025
CVE-2025-7040 on NVD →
Cloud SAML SSO <= 1.0.19 - Missing Authorization to Unauthenticated Identity Provider Deletion via delete_config Action
medium
The Cloud SAML SSO plugin for WordPress is vulnerable to Identity Provider Deletion due to a missing capability check on the delete_config action of the csso_handle_actions() function in all versions up to, and including, 1.0.19. This makes it possible for unauthenticated attackers to delete any configured IdP, breakin...
- CVSS:
- 6.5
- Affected:
- up to 1.0.19
- Fixed in:
- 1.0.20
- Disclosed:
- Sep 5, 2025
CVE-2025-7045 on NVD →
Cloud SAML SSO - Single Sign On Login <= 1.0.18 - Unauthenticated Local File Inclusion
high
The Cloud SAML SSO - Single Sign On Login plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.0.18. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be use...
- CVSS:
- 8.1
- Affected:
- up to 1.0.18
- Fixed in:
- 1.0.19
- Disclosed:
- Jul 16, 2025
CVE-2025-49264 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database