plugin

Onelogin Saml Sso Vulnerabilities

15 known security issues reported for the Onelogin Saml Sso WordPress plugin. Most recent disclosed Mar 31, 2021.

1 critical 3 high 1 medium

Running Onelogin Saml Sso on your site? Check whether your installed version is affected.

Scan your site free

OneLogin SAML SSO <= 3.1.2 - Open Redirection

medium

The OneLogin SAML SSO plugin for WordPress is vulnerable to open redirection in versions up to, and including, 3.1.2. This makes it possible for unauthorized attackers to redirect traffic to potentially malicious websites.

CVSS:
4.7
Affected:
up to 3.1.2
Fixed in:
3.2.0
Disclosed:
Mar 31, 2021

OneLogin SAML SSO [onelogin-saml-sso] < 3.2.0

unknown

The OneLogin SAML SSO plugin for WordPress is vulnerable to open redirection in versions up to, and including, 3.1.2. This makes it possible for unauthorized attackers to redirect traffic to potentially malicious websites.

Affected:
up to 3.2.0
Fixed in:
3.2.0
Disclosed:
Mar 31, 2021

OneLogin SAML SSO [onelogin-saml-sso] < 2.2.0

unknown

[en] The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provisioned users.

Affected:
up to 2.2.0
Fixed in:
2.2.0
Disclosed:
Aug 22, 2019

CVE-2016-10928 on NVD →

OneLogin SAML SSO <= 2.8.0 - Distributed Denial-of-Service

high

The OneLogin SAML SSO for WordPress is vulnerable to DDoS in versions up to, and including, 2.8.0. This is due to an XML Entity Expansion. This makes it possible for unauthenticated attackers to use XML External Entity to cause the vulnerable service to slow down and/or become unresponsive.

CVSS:
7.5
Affected:
up to 2.8.0
Fixed in:
3.0.0
Disclosed:
Jan 28, 2019

OneLogin SAML SSO [onelogin-saml-sso] < 3.0.0

unknown

The OneLogin SAML SSO for WordPress is vulnerable to DDoS in versions up to, and including, 2.8.0. This is due to an XML Entity Expansion. This makes it possible for unauthenticated attackers to use XML External Entity to cause the vulnerable service to slow down and/or become unresponsive.

Affected:
up to 3.0.0
Fixed in:
3.0.0
Disclosed:
Jan 28, 2019

OneLogin SAML SSO [onelogin-saml-sso] < 2.4.3

unknown

This plugin is prone to a signature wrapping vulnerability. Update the plugin.

Affected:
up to 2.4.3
Fixed in:
2.4.3
Disclosed:
Oct 17, 2016

OneLogin SAML SSO <= 2.4.2 - Use of Vulnerable Component

high

The OneLogin SAML SSO plugin for WordPress is potentially vulnerable to SAML Signature Wrapping attack due to use of a less secure version of the php-saml library in versions up to, and including, 2.4.2.

CVSS:
7.3
Affected:
up to 2.4.2
Fixed in:
2.4.3
Disclosed:
Oct 14, 2016

OneLogin SAML SSO [onelogin-saml-sso] < 2.4.3

unknown

The OneLogin SAML SSO plugin for WordPress is potentially vulnerable to SAML Signature Wrapping attack due to use of a less secure version of the php-saml library in versions up to, and including, 2.4.2.

Affected:
up to 2.4.3
Fixed in:
2.4.3
Disclosed:
Oct 14, 2016

OneLogin SAML-SSO Plugin < 2.1.6 - Authentication Bypass

critical

The OneLogin SAML-SSO plugin for WordPress is vulnerable to authentication bypass due to insufficient user validation in the ~/onelogin-saml-sso/onelogin_saml.php file in versions up to, and including, 2.1.5. This makes it possible for unauthenticated attackers to create new accounts, including administrator accounts i...

CVSS:
9.8
Affected:
up to 2.1.6
Fixed in:
2.1.6
Disclosed:
Jun 6, 2016

OneLogin SAML SSO [onelogin-saml-sso] < 2.1.6

unknown

This plugin has a bug which allows anyone to login without a password or other authentication. Update the plugin.

Affected:
up to 2.1.6
Fixed in:
2.1.6
Disclosed:
Jun 6, 2016

OneLogin SAML SSO [onelogin-saml-sso] < 2.1.9

unknown

This plugin is prone to a privilege escalation vulnerability. Update the plugin.

Affected:
up to 2.1.9
Fixed in:
2.1.9
Disclosed:
Jun 6, 2016

OneLogin SAML SSO [onelogin-saml-sso] < 2.1.6

unknown

The OneLogin SAML-SSO plugin for WordPress is vulnerable to authentication bypass due to insufficient user validation in the ~/onelogin-saml-sso/onelogin_saml.php file in versions up to, and including, 2.1.5. This makes it possible for unauthenticated attackers to create new accounts, including administrator accounts i...

Affected:
up to 2.1.6
Fixed in:
2.1.6
Disclosed:
Jun 6, 2016

OneLogin SAML SSO < 2.2.0 - Authentication Bypass

high

The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provisioned users.

CVSS:
7.5
Affected:
up to 2.2.0
Fixed in:
2.2.0
Disclosed:
Jan 21, 2016

CVE-2016-10928 on NVD →

OneLogin SAML SSO [onelogin-saml-sso] < 2.4.3

unknown

OneLogin SAML SSO updates php-saml library to 2.10.0 (it includes SAML Signature Wrapping attack prevention and other security improvements).

Affected:
up to 2.4.3
Fixed in:
2.4.3

OneLogin SAML SSO [onelogin-saml-sso] < 2.1.6

unknown

The OneLogin SAML SSO WordPress plugin was affected by an Authentication Bypass security vulnerability.

Affected:
up to 2.1.6
Fixed in:
2.1.6

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database