[HIGH]
·
Self-hosted / private program
·
Disclosed
Unauthenticated privilege escalation in SAML SP Single Sign On (WordPress) up to 5.4.3
Summary
A privilege escalation in the miniOrange SAML SP Single Sign On plugin for WordPress, versions up to and including 5.4.3. It can be reached without authenticating, and lets an attacker turn a low-privileged account into a higher-privileged one.
Impact
Elevated privileges on a WordPress site are the whole site: with them an attacker can take full control. Patchstack rated this 8.1.
Fix
Patched in 5.4.4.
References
- CVE-2026-61979
- Patchstack advisory: patchstack.com/database/wordpress/plugin/miniorange-saml-20-single-sign-on/vulnerability/wordpress-saml-sp-single-sign-on-plugin-5-4-3-privilege-escalation-vulnerability