Known vulnerabilities in Shibboleth
Allows WordPress to externalize user authentication and account creation to a Shibboleth Service Provider.
2Reported vulnerabilities
9.8Highest CVSS score
2.5.4Latest version
3,000+Active installs
What to do now
Update Shibboleth to 2.5.4 or later.
2 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2026-12281 | Critical | 0.4% | 2.5.3 and earlier | 2.5.4 |
June 24, 2026 |
| CVE-2017-14313 | Medium | 1.5% | 1.7 and earlier | 1.7 |
September 12, 2017 |