CVE-2026-75800: Unknown Frontegg SAML SSO
Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.
The Frontegg SAML SSO WordPress plugin through 1.0.1 does not verify the signature or issuer of SAML authentication responses before establishing a session, allowing unauthenticated attackers to log in as any user, including administrators, as well as to create arbitrary accounts.
Affected products
- Unknown Frontegg SAML SSO: up to and including 1.0.1
Published 2026-09-12. Last modified 2026-09-14.