PT-2025-36356 · WordPress · Cloud Saml Sso
Kenneth Dunn
·
Published
2025-09-06
·
Updated
2025-09-06
·
CVE-2025-7040
8.2
High
Base vector | Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions:
Cloud SAML SSO plugin for WordPress versions up to and including 1.0.19
Description:
The Cloud SAML SSO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `set organization settings` action of the `csso handle actions()` function. The handler reads client-supplied POST parameters for organization settings and passes them directly to `update option()` without verifying user capabilities or a CSRF nonce. This allows unauthenticated attackers to change critical configuration settings, potentially disrupting the SSO flow and causing a denial-of-service.
Recommendations:
Versions prior to 1.0.20: Update to a version newer than 1.0.19.
Fix
DoS
Missing Authorization
Weakness Enumeration
Related Identifiers
Affected Products
References · 14
- https://nvd.nist.gov/vuln/detail/CVE-2025-7040 · Security Note
- https://twitter.com/VulmonFeeds/status/1964201486423920647 · Twitter Post
- https://plugins.trac.wordpress.org/browser/cloud-sso-single-sign-on/tags/1.0.19/assets/base/CSSO_ActionHandler.php · Note
- https://plugins.trac.wordpress.org/browser/cloud-sso-single-sign-on/tags/1.0.19/assets/base/CSSO_services.php · Note
- https://plugins.trac.wordpress.org/browser/cloud-sso-single-sign-on/trunk/assets/base/CSSO_ActionHandler.php?rev=3354459#L202 · Note
- https://wordfence.com/threat-intel/vulnerabilities/id/59622166-3316-42e5-bf28-69eb38231755?source=cve · Note
- https://t.me/CVEtracker/31858 · Telegram Post
- https://t.me/canyoupwnme/6923 · Telegram Post
- https://twitter.com/cypmsecnews/status/1964209862037893153 · Twitter Post
- https://twitter.com/CVEnew/status/1964195390984770029 · Twitter Post
- https://wordpress.org/plugins/cloud-sso-single-sign-on/#developers · Note
- https://plugins.trac.wordpress.org/browser/cloud-sso-single-sign-on/tags/1.0.19/assets/CSSO_Init.php · Note
- https://twitter.com/RedPacketSec/status/1964187738485280927 · Twitter Post
- https://plugins.trac.wordpress.org/browser/cloud-sso-single-sign-on/tags/1.0.19/saml-sso-plugin.php · Note