Critical Alert 4 Active Exploits Detected Today

CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability →
CVE-2026-94127 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability →
CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability →
CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability →
Powered by CVE Watchtower
×

CVE Watchtower

← Back to CVE List

CVE-2026-62108Wordfence

Vulnerability Summary

The Headless SSO Plugin for WP plugin for WordPress is vulnerable to Account Takeover in all versions up to, and including, 1.7.0. This is due to a flawed account-matching condition that reduced to `username_exists($userName)` regardless of the configured matcher, allowing an IdP-asserted username to match any existing WordPress account unconditionally. This makes it possible for unauthenticated attackers to log in as any existing WordPress user, including administrators, by asserting a matching username in a crafted SAML response regardless of the configured account-matcher setting.
Severity Level
HIGH(7.3)
Published Date
Sep 17, 2026
Last Modified
Sep 22, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.40%Probability
Root Weakness (CWE)
When an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.
CVSS v3.1 Base Metrics — Score 7.3 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityLow
IntegrityLow
AvailabilityLow

Affected & Patched Versions

Affected Versions
  • Headless SSO Plugin for WP * - 1.7.0
Patched Versions
  • Headless SSO Plugin for WP 1
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.

External References