CVE-2026-19842Disclosure

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML response before storing the certificate it carries, and offers an administrator a one-click control that promotes that stored certificate to the site's trusted signing certificate, allowing unauthenticated attackers to have a certificate of their own trusted and then authenticate as any user, including an administrator.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 10 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • General: 4 classified signals
  • Peaked 3d ago at 5 mentions (2026-08-19); latest day: 1
  • 10 total mentions across 4 days

Deep dive

Activity timeline10 mentions / 4d
01345Mentions · 2026-08-19: 5Mentions · 2026-08-20: 2Mentions · 2026-08-30: 2Mentions · 2026-09-07: 1PoC Mentioned / Linked · 2026-08-30: 1Technical Details · 2026-08-19: 3Technical Details · 2026-08-20: 1Technical Details · 2026-08-30: 1Technical Details · 2026-09-07: 108-1908-2008-3009-07
Signal classification2 categories
Disclosure
660.0%
General
440.0%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-08-195
Disclosure3General2
2026-08-202
Disclosure1General1
2026-08-302
Disclosure1General1
2026-09-071
Disclosure1
Full discourse10 posts
  • Suhayb🎖@cyboltx
    Disclosure

    اللهم لك الحمد Thrilled to publish my first CVE: CVE-2026-19842 (CVSS 9.1) Unauthenticated Admin Account Takeover affecting SAML SSO WordPress plugin (v4.8.85 - 5.4.6). #CVE #WordPress #BugBounty #ATO https://t.co/dEN2igvJet

    Post summary

    The tweet announces the discovery of CVE-2026-19842, a high‑severity (CVSS 9.1) unauthenticated admin takeover vulnerability in the WordPress SAML SSO plugin, without providing PoC, exploit code, or patch details.

    2000166
    28 followersView on X
  • Suhayb🎖@cyboltx
    Disclosure

    اللهم لك الحمد Thrilled to publish my first CVE: CVE-2026-19842 (CVSS 9.1) Unauthenticated Admin Account Takeover in SAML SSO WordPress plugin (v4.8.85 - 5.4.6). Credits to @_WPScan_ for their seamless triage, coordination, and swift publication. #CVE #WordPress #BugBounty https://t.co/vJq9Vw5FQq

    Post summary

    The tweet announces the publication of CVE‑2026‑19842, a high‑severity unauthenticated admin takeover vulnerability in a WordPress SAML SSO plugin, providing basic technical details but no exploit code, patch, or evidence of exploitation.

    20001100
    28 followersView on X
  • Suhayb🎖@cyboltx
    Disclosure

    اللهم لك الحمد Thrilled to publish my first CVE: CVE-2026-19842 . Unauthenticated Admin Account Takeover affecting SAML SSO WordPress plugin (v4.8.85 - 5.4.6). #CVE #WordPress #BugBounty #ATO https://t.co/Gd4I7vdQFp

    Post summary

    The tweet announces CVE-2026-19842, describing an unauthenticated admin takeover vulnerability in the SAML SSO WordPress plugin, and includes a link that likely contains a PoC, but no exploit or patch information is provided.

    2000089
    28 followersView on X
  • Suhayb🎖@cyboltx
    Disclosure

    📝 Just published a technical deep-dive on CVE-2026-19842 Deep-dive into the code-level logic flaw behind CVE-2026-19842 (miniOrange SAML SSO). 🔗 Read the full analysis: https://medium.com/@suhaybahmedk/cve-2026-19842-deconstructing-the-saml-trust-anchor-overwrite-in-wordpress-3c52df211be9?postPublishedType=initial #AppSec #BugBounty #Cybersecurity

    Post summary

    The post announces a technical deep‑dive into CVE‑2026‑19842, detailing a logic flaw in miniOrange SAML SSO with a link to a Medium article.

    0000076
    28 followersView on X
  • Suhayb🎖@cyboltx
    General

    NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-19842 Tenable: https://www.tenable.com/cve/CVE-2026-19842 WPScan: https://wpscan.com/vulnerability/7b79d86e-d3f8-4d4f-929b-fd00540cc00f CVE: https://www.cve.org/CVERecord?id=CVE-2026-19842

    Post summary

    The statement merely lists external links related to CVE‑2026‑19842 without providing any substantive technical or operational detail.

    0000047
    28 followersView on X
  • Suhayb🎖@cyboltx
    General

    NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-19842 Tenable: https://www.tenable.com/cve/CVE-2026-19842 WPScan: https://wpscan.com/vulnerability/7b79d86e-d3f8-4d4f-929b-fd00540cc00f CVE: https://www.cve.org/CVERecord?id=CVE-2026-19842

    Post summary

    The text lists several CVE references without providing any additional details, PoC, patch, or exploitation information.

    0000030
    28 followersView on X
  • Suhayb🎖@cyboltx
    General

    Tenable: https://www.tenable.com/cve/CVE-2026-19842 NVD: https://nvd.nist.gov/vuln/detail/CVE-2026-19842 CVE: https://www.cve.org/CVERecord?id=CVE-2026-19842 WPScan: https://wpscan.com/vulnerability/7b79d86e-d3f8-4d4f-929b-fd00540cc00f

    Post summary

    The snippet provides only URLs to CVE-2026-19842 resources, lacking contextual details such as PoC, exploit code, active exploitation, patch, or technical info.

    0000072
    28 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-19842 SAML SSO WordPress Plugin Trust Issue Enables User Impersonation https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-19842

    Post summary

    The text merely lists CVE-2026-19842 with a brief headline about a trust issue leading to user impersonation, providing no further technical, exploit, or patch details.

    00000109
    4.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-19842 The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML response before storing the certificate it carries, and offers an admin… https://www.cve.org/CVERecord?id=CVE-2026-19842 ----- Traducción: CVE-2026-19842 El … https://infoflow.cloud`

    Post summary

    The tweet reports CVE-2026-19842, describing a signature‑verification flaw in the SAML Single Sign On WordPress plugin, but provides no PoC, exploit details, or patch information.

    0000027
    100 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-19842 The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML response before storing the certificate it carries, and offers an admin… https://www.cve.org/CVERecord?id=CVE-2026-19842

    Post summary

    The tweet announces a new vulnerability in the SAML Single Sign On WordPress plugin, providing technical details about its lack of signature verification, but does not mention proof‑of‑concepts, exploits, active use, or fixes.

    000001.1K
    58.0K followersView on X

Explore more