GHSA-97p7-8jv8-2rmmCriticalCVSS 9.8
The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of...
🔗 CVE IDs covered (1)
📋 Description
The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log in as any user, including administrators, as well as to create arbitrary accounts.