What is CVE-2026-15981?
CVE-2026-15981 is an Authentication Bypass vulnerability affecting the SAML Single Sign On – SSO Login plugin for WordPress up to version 5.4.4. The issue stems from the `mo_saml_validate_signature()` function performing an improper boolean check on the tri-state integer returned by PHP's `openssl_verify()`. Users should urgently update to a patched version of the plugin.
Azərbaycanca: CVE-2026-15981, WordPress üçün SAML Single Sign On – SSO Login plaginini (5.4.4 daxil olmaqla) təsir edən Authentication Bypass zəifliyidir. Səbəb `mo_saml_validate_signature()` funksiyasında PHP-nin `openssl_verify()` funksiyasından qayıdan tri-state integer dəyərinin səhv boolean yoxlanışıdır. İstifadəçilər plaginin patchlənmiş versiyasına təcili yeniləmə etməlidir.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which WordPress plugin is affected by CVE-2026-15981?
It affects the SAML Single Sign On – SSO Login plugin up to version 5.4.4.
What technical flaw underlies CVE-2026-15981?
The `mo_saml_validate_signature()` function performs an improper boolean check on the tri-state integer returned by `openssl_verify()`.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.