Known vulnerabilities in Cloud SAML SSO – Single Sign On Login
WordPress SSO using SAML IDPs to enable single sign on using Azure AD, Office 365, Okta, ADFS, KeyCloak, OneLogin, Salesforce, Google Apps Gsuite
3Reported vulnerabilities
8.2Highest CVSS score
1.0.21Latest version
80+Active installs
What to do now
Update Cloud SAML SSO – Single Sign On Login to 1.0.20 or later.
3 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2025-7040 | High | 0.3% | 0 to 1.0.19 (inclusive) | 1.0.20 |
September 6, 2025 |
| CVE-2025-49264 | High | 0.5% | 1.0.18 and earlier | 1.0.19 |
July 16, 2025 |
| CVE-2025-7045 | Medium | 0.4% | 0 to 1.0.19 (inclusive) | 1.0.20 |
September 6, 2025 |