VYPR

Shibboleth WordPress plugin

by WordPress

CVEs (1)

  • CVE-2026-12281HigJul 15, 2026
    risk 0.00cvss 8.1epss 0.00

    The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without an anti-spoofing key, treating any request that carries identity headers as an authenticated session without verifying them. On a deployment where untrusted…