26 August 2026
Reference: CVE-2026-15981
1. What is being reported?
The SAML Single Sign On plugin for WordPress has a bug that incorrectly checks login credentials. Because of this, attackers can trick the system into thinking they are a legitimate user by sending a specially crafted login request. This bypasses normal security checks and lets them access the website as if they were that user.
2. What this means in plain English
If your website uses this plugin, attackers could gain full control over your site. They might steal information, change content, or lock you out. This is especially dangerous if attackers access administrator accounts, which control the entire site.
3. Could this affect a small business?
Small businesses or organisations using WordPress with the SAML Single Sign On plugin version 5.4.4 or earlier are at risk. If you do not use this plugin, or use a different login method, this vulnerability does not affect you.
4. What to do now
- Check if your WordPress site uses the SAML Single Sign On plugin and note its version.
- If you use this plugin, update it immediately to a version newer than 5.4.4 once available.
- If an update is not yet available, consider disabling the plugin temporarily to prevent unauthorised access.
- Ask your IT provider to review your website’s login security and monitor for any unusual login activity.
5. Ask your IT provider
Can you confirm if our WordPress site uses the SAML Single Sign On plugin version 5.4.4 or earlier, and if so, have you applied the necessary updates or mitigations for CVE-2026-15981?
6. Bottom line
If you use this WordPress login plugin, act quickly to update or disable it to protect your website from unauthorised access.
Information based on NVD, CISA KEV, and reputable security reporting.