CVE-2026-75800

CVE & Vulnerabilities · September 14, 2026

CVE & Vulnerabilities·nvd.nist.gov

A flaw in the Frontegg SAML SSO plugin for WordPress, found in versions up to 1.0.1, means incoming SAML responses are accepted without any check on their signature or issuer before a session is created. As a result, an attacker who isn't even logged in can forge a session as any existing account, including an administrator, or spin up brand-new accounts on the affected site.

// source: nvd.nist.gov ↗

Back to Blog