Vulnary
← back to the feed
Critical· 9.8

CVE-2026-75800

The Frontegg SAML SSO WordPress plugin up to version 1.0.1 does not verify the signature or issuer of SAML responses, allowing attackers to log in as any user, including administrators, and create arbitrary accounts. This flaw lets unauthenticated users gain full control of the site. The vulnerability is critical with a CVSS score of 9.8.

publishedSep 12, 2026
last modifiedSep 12, 2026
sourcesNVD
severity · cvss
9.8
critical · how bad it is
exploitation · epss
<1%
8th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Oct 27, 2026

No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.

01

Who is affected

WordPress sites using the Frontegg SAML SSO plugin version 1.0.1 or earlier.

02

Real-world impact

An attacker could log in as any user, including administrators, and create new accounts, giving them full control over the WordPress site, its content, settings, and data.

03

Why this severity

The CVSS score is high because the flaw allows remote unauthenticated attackers to gain complete control—confidentiality, integrity, and availability—without any authentication or user interaction.

04

What to do about it

no official fix yet
interim mitigations
  • Upgrade the Frontegg SAML SSO plugin to a version that verifies SAML signatures and issuer information, if such a version exists. If no newer version is available, disable the plugin or restrict SSO usage until a fix is released.

No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.

NVD description

05

Timeline

06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →