External risk intelligence

Frontegg WordPress Plugin SAML SSO User Impersonation Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-75800

The vulnerability resides in a WordPress plugin responsible for SAML SSO authentication. Such identity and authentication portals are by design public-facing services meant to handle external login requests, making them inherently reachable from the internet in standard deployment configurations.

Authentication Bypass

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability impacts WordPress plugins that handle SAML single sign-on, allowing unauthorized individuals to gain access to accounts, including administrative ones, by bypassing authentication checks. The main concern at this time is confirming if your organization utilizes this specific plugin and is therefore exposed.

  • Unauthorized access to any user account.
  • Critical authentication flaw in a common plugin.
  • Confirm if this plugin is in use.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending a forged SAML response to a WordPress site using the Frontegg SAML SSO plugin. Because the plugin does not properly validate the signature or issuer of these responses, the attacker can impersonate any existing user, including administrators, or create new accounts.

  • Unauthenticated access to login endpoint.
  • Forged SAML authentication response.
  • Full account takeover and creation.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow unauthenticated attackers to compromise user accounts and potentially gain administrative access to a WordPress site. The weakness lies in how the SAML authentication responses are processed, which could enable unauthorized session establishment or account creation.

  • User account access and control.
  • Unauthenticated access to authentication responses.
  • Unauthorized user account creation or takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in the Frontegg SAML SSO WordPress plugin requires immediate attention from teams managing WordPress instances and their authentication mechanisms. The first step is to identify all WordPress sites using this plugin, determine their exposure to the internet, and confirm their business criticality. Once identified, the system owner or application owner should be engaged to plan and execute remediation, prioritizing instances that are publicly accessible or host sensitive data.

  • WordPress and application owners.
  • Verify SAML SSO plugin reachability and usage.
  • Plan phased remediation or vendor engagement.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Frontegg SAML SSO plugin for WordPress?

This software is an identity integration tool that enables WordPress sites to use Security Assertion Markup Language (SAML) for Single Sign-On (SSO). It bridges the gap between an external identity provider and a WordPress site, allowing users to log into the CMS using their existing corporate or organizational credentials instead of a separate WordPress-specific password.

What does CWE-287 mean for CVE-2026-75800?

CWE-287 refers to Improper Authentication. In the context of this CVE, it means the plugin fails to perform the essential cryptographic checks required to verify that a login request is legitimate. Because the software does not check the digital signature or the identity of the server issuing the SAML response, it mistakenly trusts forged data, essentially letting anyone claim to be any user.

How do attackers trigger this vulnerability?

An attacker triggers this by sending a malformed or forged SAML authentication response directly to the plugin. They do not need existing credentials or prior access to the system. This does not occur through normal user interaction; rather, it requires the attacker to proactively craft and submit a deceptive authentication packet that the plugin fails to reject.

Is my site at risk if it uses this plugin?

According to Halo Surface Signal, this vulnerability is very likely to be reachable because the plugin is designed to handle public login traffic. Since SAML SSO portals must accept incoming connections to function, any site running the affected plugin is inherently exposed to the internet. You should consider any instance of this plugin as a potential point of entry.

What should I do first to address CVE-2026-75800?

Your first priority is to audit your environment to create a complete inventory of every WordPress site running the Frontegg plugin. Once identified, evaluate the criticality of each site. If you cannot immediately update or replace the plugin, consider disabling SAML SSO functionality on public-facing sites to prevent unauthorized account creation and administrative takeover.

References