OneLogin SAML SSO <= 3.1.2 - Open Redirection
medium
The OneLogin SAML SSO plugin for WordPress is vulnerable to open redirection in versions up to, and including, 3.1.2. This makes it possible for unauthorized attackers to redirect traffic to potentially malicious websites.
- CVSS:
- 4.7
- Affected:
- up to 3.1.2
- Fixed in:
- 3.2.0
- Disclosed:
- Mar 31, 2021
OneLogin SAML SSO [onelogin-saml-sso] < 3.2.0
unknown
The OneLogin SAML SSO plugin for WordPress is vulnerable to open redirection in versions up to, and including, 3.1.2. This makes it possible for unauthorized attackers to redirect traffic to potentially malicious websites.
- Affected:
- up to 3.2.0
- Fixed in:
- 3.2.0
- Disclosed:
- Mar 31, 2021
OneLogin SAML SSO [onelogin-saml-sso] < 2.2.0
unknown
[en] The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provisioned users.
- Affected:
- up to 2.2.0
- Fixed in:
- 2.2.0
- Disclosed:
- Aug 22, 2019
CVE-2016-10928 on NVD →
OneLogin SAML SSO <= 2.8.0 - Distributed Denial-of-Service
high
The OneLogin SAML SSO for WordPress is vulnerable to DDoS in versions up to, and including, 2.8.0. This is due to an XML Entity Expansion. This makes it possible for unauthenticated attackers to use XML External Entity to cause the vulnerable service to slow down and/or become unresponsive.
- CVSS:
- 7.5
- Affected:
- up to 2.8.0
- Fixed in:
- 3.0.0
- Disclosed:
- Jan 28, 2019
OneLogin SAML SSO [onelogin-saml-sso] < 3.0.0
unknown
The OneLogin SAML SSO for WordPress is vulnerable to DDoS in versions up to, and including, 2.8.0. This is due to an XML Entity Expansion. This makes it possible for unauthenticated attackers to use XML External Entity to cause the vulnerable service to slow down and/or become unresponsive.
- Affected:
- up to 3.0.0
- Fixed in:
- 3.0.0
- Disclosed:
- Jan 28, 2019
OneLogin SAML SSO [onelogin-saml-sso] < 2.4.3
unknown
This plugin is prone to a signature wrapping vulnerability.
Update the plugin.
- Affected:
- up to 2.4.3
- Fixed in:
- 2.4.3
- Disclosed:
- Oct 17, 2016
OneLogin SAML SSO <= 2.4.2 - Use of Vulnerable Component
high
The OneLogin SAML SSO plugin for WordPress is potentially vulnerable to SAML Signature Wrapping attack due to use of a less secure version of the php-saml library in versions up to, and including, 2.4.2.
- CVSS:
- 7.3
- Affected:
- up to 2.4.2
- Fixed in:
- 2.4.3
- Disclosed:
- Oct 14, 2016
OneLogin SAML SSO [onelogin-saml-sso] < 2.4.3
unknown
The OneLogin SAML SSO plugin for WordPress is potentially vulnerable to SAML Signature Wrapping attack due to use of a less secure version of the php-saml library in versions up to, and including, 2.4.2.
- Affected:
- up to 2.4.3
- Fixed in:
- 2.4.3
- Disclosed:
- Oct 14, 2016
OneLogin SAML-SSO Plugin < 2.1.6 - Authentication Bypass
critical
The OneLogin SAML-SSO plugin for WordPress is vulnerable to authentication bypass due to insufficient user validation in the ~/onelogin-saml-sso/onelogin_saml.php file in versions up to, and including, 2.1.5. This makes it possible for unauthenticated attackers to create new accounts, including administrator accounts i...
- CVSS:
- 9.8
- Affected:
- up to 2.1.6
- Fixed in:
- 2.1.6
- Disclosed:
- Jun 6, 2016
OneLogin SAML SSO [onelogin-saml-sso] < 2.1.6
unknown
This plugin has a bug which allows anyone to login without a password or other authentication.
Update the plugin.
- Affected:
- up to 2.1.6
- Fixed in:
- 2.1.6
- Disclosed:
- Jun 6, 2016
OneLogin SAML SSO [onelogin-saml-sso] < 2.1.9
unknown
This plugin is prone to a privilege escalation vulnerability.
Update the plugin.
- Affected:
- up to 2.1.9
- Fixed in:
- 2.1.9
- Disclosed:
- Jun 6, 2016
OneLogin SAML SSO [onelogin-saml-sso] < 2.1.6
unknown
The OneLogin SAML-SSO plugin for WordPress is vulnerable to authentication bypass due to insufficient user validation in the ~/onelogin-saml-sso/onelogin_saml.php file in versions up to, and including, 2.1.5. This makes it possible for unauthenticated attackers to create new accounts, including administrator accounts i...
- Affected:
- up to 2.1.6
- Fixed in:
- 2.1.6
- Disclosed:
- Jun 6, 2016
OneLogin SAML SSO < 2.2.0 - Authentication Bypass
high
The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provisioned users.
- CVSS:
- 7.5
- Affected:
- up to 2.2.0
- Fixed in:
- 2.2.0
- Disclosed:
- Jan 21, 2016
CVE-2016-10928 on NVD →
OneLogin SAML SSO [onelogin-saml-sso] < 2.4.3
unknown
OneLogin SAML SSO updates php-saml library to 2.10.0 (it includes SAML Signature Wrapping attack prevention and other security improvements).
- Affected:
- up to 2.4.3
- Fixed in:
- 2.4.3
OneLogin SAML SSO [onelogin-saml-sso] < 2.1.6
unknown
The OneLogin SAML SSO WordPress plugin was affected by an Authentication Bypass security vulnerability.
- Affected:
- up to 2.1.6
- Fixed in:
- 2.1.6
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database