CVE-2016-10928: High severity onelogin Onelogin Saml Sso Wordpress vulnerability
Published Aug 22, 2019
·Updated
The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provisioned users.
Affected Software
1 affected component
onelogin Onelogin Saml Sso Wordpress<2.2.0
Remediation
Event History
Aug 22, 2019
CVE Published
via MITRE·07:40 PM
Data Sourced
via MITRE·07:40 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10928?
CVE-2016-10928 has a medium severity level due to the hardcoded password vulnerability.
2
How do I fix CVE-2016-10928?
To fix CVE-2016-10928, update the onelogin-saml-sso plugin to version 2.2.0 or later.
3
Who is affected by CVE-2016-10928?
CVE-2016-10928 affects WordPress installations using versions of the onelogin-saml-sso plugin prior to 2.2.0.
4
What are the risks of CVE-2016-10928?
The risks of CVE-2016-10928 include unauthorized access to just-in-time provisioned user accounts due to the hardcoded password.
5
Can CVE-2016-10928 be exploited remotely?
Yes, CVE-2016-10928 can be exploited remotely by attackers who access the vulnerable plugin.