CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.5. It affects WordPress. Exploitation may require the attacker to be authenticated. It may lead to a denial-of-service condition.
CVE
CVE-2025-7045
Severity
MEDIUM
CVSS
6.5
EPSS
0.37%
WordPress
Original NVD Description
The Cloud SAML SSO plugin for WordPress is vulnerable to Identity Provider Deletion due to a missing capability check on the delete_config action of the csso_handle_actions() function in all versions up to, and including, 1.0.19. This makes it possible for unauthenticated attackers to delete any configured IdP, breaking the SSO authentication flow and causing a denial-of-service.