← Back to CVE List
CVE-2026-62108Wordfence
Vulnerability Summary
The Headless SSO Plugin for WP plugin for WordPress is vulnerable to Account Takeover in all versions up to, and including, 1.7.0. This is due to a flawed account-matching condition that reduced to `username_exists($userName)` regardless of the configured matcher, allowing an IdP-asserted username to match any existing WordPress account unconditionally. This makes it possible for unauthenticated attackers to log in as any existing WordPress user, including administrators, by asserting a matching username in a crafted SAML response regardless of the configured account-matcher setting.
CVSS v3.1 Base Metrics — Score 7.3 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityLow
IntegrityLow
AvailabilityLow
Affected & Patched Versions
- Headless SSO Plugin for WP * - 1.7.0
- Headless SSO Plugin for WP 1