CVE-2023-41873: WordPress SAML Single Sign On – SSO Login plugin <= 5.0.4 - Broken Access Control vulnerability
Missing Authorization vulnerability in miniOrange SAML SP Single Sign On miniorange-saml-20-single-sign-on allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SAML SP Single Sign On: from n/a through <= 5.0.4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-41873?
CVE-2023-41873 is classified as a Missing Authorization security vulnerability.
How do I fix CVE-2023-41873?
To fix CVE-2023-41873, update the miniOrange SAML SP Single Sign On plugin to version 5.0.5 or later.
What versions are affected by CVE-2023-41873?
CVE-2023-41873 affects the miniOrange SAML SP Single Sign On versions up to and including 5.0.4.
Can CVE-2023-41873 be exploited on WordPress?
Yes, CVE-2023-41873 can be exploited on the WordPress SAML Single Sign On – SSO Login plugin up to version 5.0.4.
What are the consequences of CVE-2023-41873?
Exploiting CVE-2023-41873 can lead to unauthorized access due to incorrectly configured access control security levels.