CVE detail
CVE-2019-12346 — CVE-2019-12346
Published 2019-06-24 · Modified 2026-06-17 · Vendor miniorange · Product saml_sp_single_sign_on · Source nvd
MEDIUM
severity
CVSS-derived band
0.0107
EPSS probability
exploitation probability, 30d
62.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
In the miniOrange SAML SP Single Sign On plugin before 4.8.73 for WordPress, the SAML Login Endpoint is vulnerable to XSS via a specially crafted SAMLResponse XML post.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References