CyberRota Analysis
AI-GeneratedThe Frontegg SAML SSO WordPress plugin versions up to 1.0.1 are vulnerable due to inadequate verification of SAML authentication response signatures and issuers, enabling unauthenticated attackers to log in as any user, including administrators, and create arbitrary accounts. This critical flaw poses a significant security risk, particularly for WordPress sites utilizing this plugin for user authentication. WordPress administrators and security teams should prioritize patching or disabling this plugin to mitigate potential unauthorized access.
Original NVD Description
The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log in as any user, including administrators, as well as to create arbitrary accounts.