8.1
CVE-2026-61979
- EPSS 0.27%
- Veröffentlicht 13.08.2026 13:36:45
- Zuletzt bearbeitet 14.08.2026 19:09:20
- Erkennungen
WordPress SAML SP Single Sign On plugin <= 5.4.3 - Privilege Escalation vulnerability
SAML Single Sign On – SSO Login <= 5.4.3 - Unauthenticated Privilege Escalation
Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions.
Mögliche Gegenmaßnahme
SAML Single Sign On – SSO Login: Update to version 5.4.4, or a newer patched version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerminiOrange
≫
Produkt
SAML SP Single Sign On
Default Statusunaffected
Version <=
5.4.3
Version
n/a
Status
affected
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemWordPress Plugin
≫
Produkt
SAML Single Sign On – SSO Login
Version
*-5.4.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.27% | 0.194 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| audit@patchstack.com | 8.1 | 2.2 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-266 Incorrect Privilege Assignment
A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://patchstack.com/database/wordpress/plugin/miniorange-saml-20-single-sign-on/vulnerability/wordpress-saml-sp-single-sign-on-plugin-5-4-3-privilege-escalation-vulnerability?_s_id=cve
https://www.wordfence.com/threat-intel/vulnerabilities/id/cb03eb79-27c9-4a9d-b690-71946e11f39f