CVE-2026-15013

CRITICAL

SAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm Confusion

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-15013. PoCs published by zer0dayf.

AI-analyzed exploit summary This PoC exploits CVE-2026-15013, an authentication bypass vulnerability in miniOrange SAML SSO WordPress plugin (<=5.4.3) via HMAC signature algorithm confusion. The exploit forges SAML assertions using the IdP's RSA public key as an HMAC shared secret, enabling unauthenticated admin access and arbitrary command execution via webshell or reverse shell.

Description

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all versions up to, and including, 5.4.3. The vulnerability exists because `Mo_SAML_Utilities::mo_saml_cast_key()` reads the `SignatureMethod` Algorithm attribute directly from the attacker-controlled `SAMLResponse` parameter rather than enforcing the locally configured algorithm, causing the plugin to recast the IdP's RSA public key as an HMAC-SHA1 shared secret and validate the forged signature against it. This makes it possible for unauthenticated attackers to forge a SAML assertion targeting any WordPress account — including administrators — obtain valid WordPress authentication cookies, and achieve full administrator-level account takeover.

Exploits (1)

github WORKING POC
by zer0dayf · pythonpoc
https://github.com/zer0dayf/CVE-2026-15013

This PoC exploits CVE-2026-15013, an authentication bypass vulnerability in miniOrange SAML SSO WordPress plugin (<=5.4.3) via HMAC signature algorithm confusion. The exploit forges SAML assertions using the IdP's RSA public key as an HMAC shared secret, enabling unauthenticated admin access and arbitrary command execution via webshell or reverse shell.

Classification
Working Poc 99%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: miniOrange SAML Single Sign On – SSO Login WordPress plugin <=5.4.3
No auth needed
Prerequisites: Target must be running vulnerable plugin version (<=5.4.3) · Attacker must have access to IdP's public certificate (often available via metadata) · Target WordPress site must have at least one admin user account
mistral-large-3 · analyzed Jul 27, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.0044
EPSS Percentile 35.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-347
Status published
Products (1)
cyberlord92/SAML Single Sign On – SSO Login < 5.4.3
Published Jul 16, 2026
Tracked Since Jul 16, 2026