Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-12281— Shibboleth < 2.5.4 - Unauthenticated Administrator Account Creation via Identity Header Spoofing

Quick assessment

Affected
Unknown Shibboleth
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress Shibboleth是WordPress基金会的一个身份认证插件。 WordPress Shibboleth 2.5.4之前版本存在授权问题漏洞,该漏洞源于启用HTTP标头身份模式时未设置反欺骗密钥,无法正确验证身份信息,可能导致未经验证的攻击者通过伪造的身份标头登录,并在自动账户创建和默认管理员角色映射开启时,创建并登录为新的管理员。

AI Predicted 9.8 Difficulty: Easy EPSS 0.38% · P30

Affected Version Matrix 1

VendorProduct Version RangeStatus
Unknown Shibboleth < 2.5.4 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-12281

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Shibboleth < 2.5.4 - Unauthenticated Administrator Account Creation via Identity Header Spoofing
Source: CVE Program / CVE List V5
Vulnerability Description
The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without an anti-spoofing key, treating any request that carries identity headers as an authenticated session without verifying them. On a deployment where untrusted client headers reach the application, an unauthenticated attacker can log in with forged identity headers and, when automatic account creation and the default administrator role mapping are enabled, create and sign in as a new administrator. Exploitation requires the non-default HTTP header attribute mode, an empty or absent spoof key, automatic account creation enabled, and a deployment that does not strip untrusted client headers before they reach the application.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
WordPress Shibboleth 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
WordPress Shibboleth是WordPress基金会的一个身份认证插件。 WordPress Shibboleth 2.5.4之前版本存在授权问题漏洞,该漏洞源于启用HTTP标头身份模式时未设置反欺骗密钥,无法正确验证身份信息,可能导致未经验证的攻击者通过伪造的身份标头登录,并在自动账户创建和默认管理员角色映射开启时,创建并登录为新的管理员。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Unknown Shibboleth 0 ~ 2.5.4 -

II. Public POCs for CVE-2026-12281

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-12281

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-12281 (1)

Same Patch Batch · Unknown · 2026-07-15 · 4 CVEs total

CVE-2026-11579 Kali Forms < 2.4.17 - Unauthenticated Media Upload
CVE-2026-11580 Kali Forms < 2.4.17 - Contributor+ Arbitrary Post Metadata Disclosure via IDOR
CVE-2026-12512 Quotes Llama < 3.1.6 - Unauthenticated SQL Injection via sc Parameter

IV. Related Vulnerabilities

V. Comments for CVE-2026-12281

No comments yet


Leave a comment