SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-75800

CRITICAL · CVSS 9.8 EPSS 0.42%

Source: NVD + CISA KEV + EPSS · Published 2026-09-12 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The Frontegg SAML SSO WordPress plugin versions up to 1.0.1 are vulnerable due to inadequate verification of SAML authentication response signatures and issuers, enabling unauthenticated attackers to log in as any user, including administrators, and create arbitrary accounts. This critical flaw poses a significant security risk, particularly for WordPress sites utilizing this plugin for user authentication. WordPress administrators and security teams should prioritize patching or disabling this plugin to mitigate potential unauthorized access.

CVE
CVE-2026-75800
Severity
CRITICAL
CVSS
9.8
EPSS
0.42%
WordPress

Original NVD Description

The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log in as any user, including administrators, as well as to create arbitrary accounts.