Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 20 Sep 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 CWE-285 CWE-639 |
Sun, 20 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-269 | |
| Metrics |
cvssV3_1
|
Sun, 20 Sep 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-20 CWE-285 CWE-639 |
Sun, 20 Sep 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The SAML Single Sign On WordPress plugin before 6.0.0 does not honour the configured criterion for linking an incoming single sign-on identity to a WordPress account, always resolving the identity by login name whatever the site has chosen, which allows an attacker who can have the site's identity provider assert a login name of their choosing to authenticate as any account, including an administrator, without proving ownership of that account. | |
| Title | SAML Single Sign On < 6.0.0 - Unauthenticated Privilege Escalation via Account Matching | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-20T13:49:00.235Z
Reserved: 2026-08-31T08:27:11.846Z
Link: CVE-2026-82842
Updated: 2026-09-20T13:48:43.359Z
Status : Received
Published: 2026-09-20T07:16:50.093
Modified: 2026-09-20T14:16:58.390
Link: CVE-2026-82842
No data.
OpenCVE Enrichment
Updated: 2026-09-20T16:00:14Z
-
CWE-269
Improper Privilege Management