WordPress 的 SAML 单点登录(SSO)插件在 5.4.6 及更早版本中存在身份验证绕过漏洞。该漏洞的成因在于, ACS 处理程序在强制执行签名验证结果之前,将从传入的 SAMLResponse 中提取的 X.509 证书持久化存储到 选项中,因为当指纹不匹配时, 仅返回 false 而未停止执行流程。这使得未认证的攻击者可以用攻击者控制的值覆盖插件中存储的 IdP 签名证书,随后即可伪造任意 WordPress 账户(包括管理员账户)的 SAML 断言,从而获取完全受权的会话。注意:利用该漏洞需要管理
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| cyberlord92 | SAML Single Sign On – SSO Login | ≤ 5.4.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| cyberlord92 | SAML Single Sign On – SSO Login | 0 ~ 5.4.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet