Medium 6.5
2025-09-06< 1.0.20
Cloud SAML SSO <= 1.0.19 - Missing Authorization to Unauthenticated Identity Provider Deletion via delete_config Action
Minimum safe version
1.0.20
Update to 1.0.20 or later to address 4 fixable vulnerabilities
Cloud SAML SSO <= 1.0.19 - Missing Authorization to Unauthenticated Identity Provider Deletion via delete_config Action
Cloud SAML SSO <= 1.0.19 - Missing Authorization to Unauthenticated Settings Modification via set_organization_settings Action
CVE-2025-49264
WordPress Cloud SAML SSO - Single Sign On Login Plugin < 1.0.14 is vulnerable to Cross Site Scripting (XSS)