Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

Critical Security Flaw in WordPress Login Plugin Allows Hackers to Access Your Site

A serious security weakness has been found in a popular WordPress plugin used for Single Sign-On (SSO) login. This flaw could let attackers log in as any user, including administrators, without needing a password. This puts your website and data at risk.

26 August 2026

Reference: CVE-2026-15981

1. What is being reported?

The SAML Single Sign On plugin for WordPress has a bug that incorrectly checks login credentials. Because of this, attackers can trick the system into thinking they are a legitimate user by sending a specially crafted login request. This bypasses normal security checks and lets them access the website as if they were that user.

2. What this means in plain English

If your website uses this plugin, attackers could gain full control over your site. They might steal information, change content, or lock you out. This is especially dangerous if attackers access administrator accounts, which control the entire site.

3. Could this affect a small business?

Small businesses or organisations using WordPress with the SAML Single Sign On plugin version 5.4.4 or earlier are at risk. If you do not use this plugin, or use a different login method, this vulnerability does not affect you.

4. What to do now

  • Check if your WordPress site uses the SAML Single Sign On plugin and note its version.
  • If you use this plugin, update it immediately to a version newer than 5.4.4 once available.
  • If an update is not yet available, consider disabling the plugin temporarily to prevent unauthorised access.
  • Ask your IT provider to review your website’s login security and monitor for any unusual login activity.

5. Ask your IT provider

Can you confirm if our WordPress site uses the SAML Single Sign On plugin version 5.4.4 or earlier, and if so, have you applied the necessary updates or mitigations for CVE-2026-15981?

6. Bottom line

If you use this WordPress login plugin, act quickly to update or disable it to protect your website from unauthorised access.

Information based on NVD, CISA KEV, and reputable security reporting.

Back to Vulnerability Briefs