CVE-2026-75800
Received Received - Intake

Authentication Bypass via SAML in Frontegg WordPress Plugin

Vulnerability report for CVE-2026-75800, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-12

Last updated on: 2026-09-12

Assigner: WPScan

Description

The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log in as any user, including administrators, as well as to create arbitrary accounts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-12
Last Modified
2026-09-12
Generated
2026-09-12
AI Q&A
2026-09-12
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
frontegg saml_sso to 1.0.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Frontegg SAML SSO WordPress plugin through version 1.0.1 has a critical flaw where it does not verify the signature or issuer of SAML authentication responses. This allows unauthenticated attackers to bypass login mechanisms and gain access to any user account, including administrators, or create new accounts without credentials.

Detection Guidance

Detecting this vulnerability requires checking if the Frontegg SAML SSO WordPress plugin version 1.0.1 or below is installed. Inspect WordPress plugins via the admin dashboard or use commands like 'wp plugin list' in the WordPress directory. Verify if SAML responses are being logged or monitored for missing signature or issuer validation.

Impact Analysis

This vulnerability enables attackers to take over any user account on your WordPress site, including admin accounts, without needing valid credentials. They can also create new accounts with full access, leading to complete site compromise, data theft, or malicious actions being performed under your identity.

Compliance Impact

This vulnerability severely impacts compliance with GDPR and HIPAA by allowing unauthorized access to sensitive user data. It violates principles of data protection, access control, and authentication, potentially leading to regulatory fines, legal liabilities, and loss of trust due to unauthorized data exposure or breaches.

Mitigation Strategies

Immediately disable the Frontegg SAML SSO WordPress plugin if installed. Monitor for unauthorized account creation or login attempts. Check for suspicious admin accounts or new user registrations without credentials.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75800. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart