plugin

Miniorange Saml 20 Single Sign On Vulnerabilities

27 known security issues reported for the Miniorange Saml 20 Single Sign On WordPress plugin. Most recent disclosed Aug 29, 2026.

3 critical 3 high 12 medium

Running Miniorange Saml 20 Single Sign On on your site? Check whether your installed version is affected.

Scan your site free

SAML Single Sign On <= 5.4.6 - Unauthenticated Authentication Bypass via X.509 Certificate Poisoning

high

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 5.4.6. This is due to the mo_saml_login_validate() ACS handler persisting the X.509 certificate extracted from an incoming SAMLResponse into the mo_saml_required_certificate option before th...

CVSS:
7.5
Affected:
up to 5.4.6
Fixed in:
5.4.7
Disclosed:
Aug 29, 2026

CVE-2026-75807 on NVD →

SAML Single Sign On – SSO Login 4.8.85-5.4.6 - Unauthenticated Privilege Escalation

high

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to 4.8.85-5.4.6. This is due to insufficient restriction on the capabilities a user may grant themselves. This makes it possible for unauthenticated attackers to elevate their privileges beyond those intend...

CVSS:
7.3
Affected:
4.8.85 – 5.4.6
Fixed in:
5.4.7
Disclosed:
Aug 19, 2026

CVE-2026-19842 on NVD →

SAML Single Sign On – SSO Login <= 5.4.3 - Unauthenticated Privilege Escalation

critical

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.4.3. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.

CVSS:
9.8
Affected:
up to 5.4.3
Fixed in:
5.4.4
Disclosed:
Aug 13, 2026

CVE-2026-61979 on NVD →

SAML Single Sign On <= 5.4.4 - Unauthenticated Authentication Bypass via SAMLResponse Parameter

critical

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's openssl_verify(), causing an error return...

CVSS:
9.8
Affected:
up to 5.4.4
Fixed in:
5.4.5
Disclosed:
Jul 23, 2026

CVE-2026-15981 on NVD →

SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm Confusion

critical

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3. The vulnerability exists because `Mo_SAML_Utilities::mo_saml_cast_key()` reads the `SignatureMethod` Algorithm attribute directly from the a...

CVSS:
9.8
Affected:
up to 5.4.3
Fixed in:
5.4.4
Disclosed:
Jul 15, 2026

CVE-2026-15013 on NVD →

SAML Single Sign On – SSO Login [miniorange-saml-20-single-sign-on] < 5.0.5

unknown

[en] Missing Authorization vulnerability in miniOrange SAML SP Single Sign On allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SAML SP Single Sign On: from n/a through 5.0.4.

Affected:
up to 5.0.5
Fixed in:
5.0.5
Disclosed:
Dec 13, 2024

CVE-2023-41873 on NVD →

SAML SP Single Sign On <= 5.0.4 - Missing Authorization to notice dismissal

medium

The SAML SP Single Sign On plugin for WordPress is vulnerable to unauthorized notice dismissal due to a missing capability check on the close_welcome_modal function in versions up to, and including, 5.0.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to dismiss the welcome...

CVSS:
4.3
Affected:
up to 5.0.4
Fixed in:
5.0.5
Disclosed:
Sep 5, 2023

CVE-2023-41873 on NVD →

SAML SP Single Sign On < 5.0.5 - Missing Authorization to notice dismissal

medium
Affected:
up to 5.0.5
Fixed in:
5.0.5
Disclosed:
Sep 5, 2023

CVE-2023-41873 on NVD →

SAML Single Sign On – SSO Login [miniorange-saml-20-single-sign-on] < 4.9.32

unknown

[en] The SAML SSO Standard WordPress plugin version 16.0.0 before 16.0.8, SAML SSO Premium WordPress plugin version 12.0.0 before 12.1.0 and SAML SSO Premium Multisite WordPress plugin version 20.0.0 before 20.0.7 does not validate that the redirect parameter to its SSO login endpoint points to an internal site URL, ma...

Affected:
up to 4.9.32
Fixed in:
4.9.32
Disclosed:
Jan 30, 2023

CVE-2022-4496 on NVD →

SAML Single Sign On – SSO Login Premium Multisite < 20.0.7 - Open Redirect

medium

The SSO Login Premium Multisite plugin for WordPress is vulnerable to Open Redirect in versions up to, and including, 20.0.7 due to missing validation of its redirect parameter. This makes it possible for an attacker to redirect authenticated users. This vulnerability also affects the Premium Edition (versions <12.1.0...

CVSS:
6.1
Affected:
20 – 20.0.7
Fixed in:
20.0.7
Disclosed:
Jan 6, 2023

CVE-2022-4496 on NVD →

miniOrange WordPress SAML SSO Standard < 16.0.8 - Open Redirect in SSO login

medium
Affected:
16.0.0 – 16.0.8
Fixed in:
16.0.8
Disclosed:
Jan 6, 2023

CVE-2022-4496 on NVD →

miniOrange WordPress SAML SSO Premium < 12.1.0 - Open Redirect in SSO login

medium
Affected:
12.0.0 – 12.1.0
Fixed in:
12.1.0
Disclosed:
Jan 6, 2023

CVE-2022-4496 on NVD →

miniOrange WordPress SAML SSO Premium Multisite < 20.0.7 - Open Redirect in SSO login

medium
Affected:
20.0.0 – 20.0.7
Fixed in:
20.0.7
Disclosed:
Jan 6, 2023

CVE-2022-4496 on NVD →

SAML Single Sign On – SSO Login [miniorange-saml-20-single-sign-on] < 4.9.21

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress SAML Single Sign On – SAML SSO Login plugin (versions <= 4.9.20). Update the WordPress SAML Single Sign On – SAML SSO Login plugin to the latest available version (at least 4.9.21).

Affected:
up to 4.9.21
Fixed in:
4.9.21
Disclosed:
Jun 7, 2022

SAML Single Sign On – SAML SSO Login <= 4.9.20 - Reflected Cross-Site Scripting

medium

The SAML Single Sign On – SAML SSO Login plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 4.9.20. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...

CVSS:
6.1
Affected:
up to 4.9.20
Fixed in:
4.9.21
Disclosed:
Jun 6, 2022

SAML Single Sign On – SSO Login [miniorange-saml-20-single-sign-on] < 4.9.21

unknown

The SAML Single Sign On – SAML SSO Login plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in versions up to, and including, 4.9.20. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th...

Affected:
up to 4.9.21
Fixed in:
4.9.21
Disclosed:
Jun 6, 2022

SAML Single Sign On – SSO Login [miniorange-saml-20-single-sign-on] < 4.8.84

unknown

[en] Utilities.php in the miniorange-saml-20-single-sign-on plugin before 4.8.84 for WordPress allows XSS via a crafted SAML XML Response to wp-login.php. This is related to the SAMLResponse and RelayState variables, and the Destination parameter of the samlp:Response XML element.

Affected:
up to 4.8.84
Fixed in:
4.8.84
Disclosed:
Feb 17, 2020

CVE-2020-6850 on NVD →

SAML Single Sign On – SAML SSO Login <= 4.8.83 - Cross-Site Scripting

medium

Utilities.php in the miniorange-saml-20-single-sign-on plugin before 4.8.84 for WordPress allows XSS via a crafted SAML XML Response to wp-login.php. This is related to the SAMLResponse and RelayState variables, and the Destination parameter of the samlp:Response XML element.

CVSS:
6.1
Affected:
up to 4.8.83
Fixed in:
4.8.84
Disclosed:
Jan 28, 2020

CVE-2020-6850 on NVD →

SAML SP Single Sign On < 4.8.84 - Cross-Site Scripting (XSS) via Crafted SAML XML Response

medium
Affected:
up to 4.8.84
Fixed in:
4.8.84
Disclosed:
Jan 28, 2020

CVE-2020-6850 on NVD →

SAML Single Sign On – SSO Login [miniorange-saml-20-single-sign-on] < 4.8.73

unknown

Cross-Site Scripting (XSS) vulnerability found by ZEROAUTH in WordPress SAML SP Single Sign On plugin (versions <= 4.8.72).

Affected:
up to 4.8.73
Fixed in:
4.8.73
Disclosed:
Jun 27, 2019

SAML Single Sign On – SSO Login [miniorange-saml-20-single-sign-on] < 4.8.73

unknown

[en] In the miniOrange SAML SP Single Sign On plugin before 4.8.73 for WordPress, the SAML Login Endpoint is vulnerable to XSS via a specially crafted SAMLResponse XML post.

Affected:
up to 4.8.73
Fixed in:
4.8.73
Disclosed:
Jun 24, 2019

CVE-2019-12346 on NVD →

SAML Single Sign On – SAML SSO Login < 4.8.73 - Cross-Site Scripting

medium

In the miniOrange SAML SP Single Sign On plugin before 4.8.73 for WordPress, the SAML Login Endpoint is vulnerable to XSS via a specially crafted SAMLResponse XML post.

CVSS:
6.1
Affected:
up to 4.8.73
Fixed in:
4.8.73
Disclosed:
May 27, 2019

CVE-2019-12346 on NVD →

SAML SP Single Sign On <= 4.8.72 - Cross-Site Scripting (XSS)

medium
Affected:
up to 4.8.73
Fixed in:
4.8.73
Disclosed:
May 27, 2019

CVE-2019-12346 on NVD →

SAML Single Sign On – SAML SSO Login <= 4.8.75 - Cross-Site Request Forgery

high

The SAML Single Sign On plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.8.75. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to gain otherwise restricted access to administrative actions via a forged request...

CVSS:
8.8
Affected:
up to 4.8.75
Fixed in:
4.8.76
Disclosed:
May 20, 2019

SAML Single Sign On – SSO Login [miniorange-saml-20-single-sign-on] < 4.8.76

unknown

The SAML Single Sign On plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.8.75. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to gain otherwise restricted access to administrative actions via a forged request...

Affected:
up to 4.8.76
Fixed in:
4.8.76
Disclosed:
May 20, 2019

SAML SP SSO < 4.8.74 - Multiple Cross-Site Request Forgery (CSRF)

medium
Affected:
up to 4.8.74
Fixed in:
4.8.74
Disclosed:
May 16, 2019

SAML Single Sign On – SSO Login [miniorange-saml-20-single-sign-on] < 4.8.74

unknown

The SAML Single Sign On &ndash; SSO Login WordPress plugin was affected by a Multiple Cross-Site Request Forgery (CSRF) security vulnerability.

Affected:
up to 4.8.74
Fixed in:
4.8.74

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database