CRITICAL

CVE-2026-15981

CVSS v3

9.8

CRITICAL

EPSS Score

0.5%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's openssl_verify(), causing an error return value of -1 to be evaluated as truthy and therefore treated as a successful signature verification. This makes it possible for unauthenticated attackers to log in as any existing W

Technical details

CVSS v3 Vector
3.1
Published
7/23/2026
Last Modified
7/23/2026

Frequently asked questions

What is CVE-2026-15981?

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's openssl_verify(), causing an error return value of -1 to be evaluated as truthy and therefore treated as a successful signature verification. This makes it possible for unauthenticated attackers to log in as any existing W

Is CVE-2026-15981 actively exploited?

Active exploitation of CVE-2026-15981 has not been confirmed. The EPSS score is 0.5%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-15981?

CVE-2026-15981 has a CVSS v3 base score of 9.8 (CRITICAL severity), with vector string 3.1.

Is CVE-2026-15981 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.