Skip to content
RedPacket Security

RedPacket Security

InfoSec News & Tutorials

Primary Menu RedPacket Security

RedPacket Security

  • Home
  • Merch
  • Premium Members Content
    • Offensive SecurityOffensive Security focuses on proactively testing and strengthening cybersecurity by simulating real-world attacks. This category covers penetration testing, ethical hacking techniques, exploit development, red teaming, and adversarial tactics used to identify and fix vulnerabilities before malicious actors exploit them. Whether you’re a cybersecurity professional, ethical hacker, or enthusiast, you’ll find expert insights, tools, methodologies, and case studies to enhance your offensive security skills. Stay ahead of threats by learning how attackers think and operate, ensuring robust defence through strategic offence
    • Threat Hunting
    • TutorialsTutorials
    • Hack The BoxGuides / Tutorials on Hack The Box https://www.hackthebox.eu/home
    • Try Hack MeGuides / Tutorials on Try Hack Me These posts are password protected. To obtain the password you will need to become a patreon:
  • News
    • US-CERT
    • HKCERT
    • OSINT
    • CISA
    • NCSC
  • Data Breach
    • Ransomware
  • Malware Analysis
    • Covenant C2
    • Cobalt Strike
    • Brute Ratel C4
    • Posh C2
    • PikaBot C2
    • SliverC2
  • Vulnerabilities
    • Bug Bounty
  • Tools
  • Home
  • Vulnerabilities
  • CVE Alert: CVE-2025-7040 – cloudinfrastructureservices – Cloud SAML SSO – Single Sign On Login
  • Vulnerabilities

CVE Alert: CVE-2025-7040 – cloudinfrastructureservices – Cloud SAML SSO – Single Sign On Login

September 6, 2025

CVE-2025-7040

HIGHNo exploitation known

The Cloud SAML SSO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ‘set_organization_settings’ action of the csso_handle_actions() function in all versions up to, and including, 1.0.19. The handler reads client-supplied POST parameters for organization settings and passes them directly to update_option() without any check of the user’s capabilities or a CSRF nonce. This makes it possible for unauthenticated attackers to change critical configuration (including toggling signing and encryption), potentially breaking the SSO flow and causing a denial-of-service.

CVSS v3.1 (8.2)
Vendor
cloudinfrastructureservices
Product
Cloud SAML SSO – Single Sign On Login
Versions
* lte 1.0.19
CWE
CWE-862, CWE-862 Missing Authorization
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
Published
2025-09-06T03:22:36.142Z
Updated
2025-09-06T03:22:36.142Z
References
https://www.wordfence.com/threat-intel/vulnerabilities/id/59622166-3316-42e5-bf28-69eb38231755?source=cve
https://wordpress.org/plugins/cloud-sso-single-sign-on/#developers
https://plugins.trac.wordpress.org/browser/cloud-sso-single-sign-on/tags/1.0.19/assets/base/CSSO_ActionHandler.php
https://plugins.trac.wordpress.org/browser/cloud-sso-single-sign-on/tags/1.0.19/assets/base/CSSO_services.php
https://plugins.trac.wordpress.org/browser/cloud-sso-single-sign-on/tags/1.0.19/assets/CSSO_Init.php
https://plugins.trac.wordpress.org/browser/cloud-sso-single-sign-on/tags/1.0.19/saml-sso-plugin.php
https://plugins.trac.wordpress.org/browser/cloud-sso-single-sign-on/trunk/assets/base/CSSO_ActionHandler.php?rev=3354459#L202

AI Summary Analysis

Risk verdict

Why this matters

Most likely attack path

Who is most exposed

Detection ideas

  • Unauthorised POSTs to set_organization_settings in the plugin’s action handler.
  • Unexpected changes to organization settings or SSO configuration (signing/encryption toggles) in wp_options or related logs.
  • Absence of CSRF nonce checks or capability validation in CSSO_ActionHandler.php.
  • Admin-ajax or plugin endpoints accessed without authenticated sessions.
  • Anomalous admin activity coinciding with config changes.

Mitigation and prioritisation

  • Apply the patched version (1.0.19) or newer; if unavailable, disable the plugin until fixed.
  • Enforce authentication and proper capability checks for set_organization_settings; add CSRF nonce validation.
  • Implement WAF/IPS rules to block unauthenticated attempts to invoke the action.
  • Audit and constrain admin-access to the WordPress instance; review and revert unintended config changes.
  • Schedule testing in staging, then controlled production rollout; update change-management tickets.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on “Patreon” or “Buy Me A Coffee” using the buttons below

Buy Me A Coffee
Patreon

To keep up to date follow us on the below channels.

Telegram Discord Reddit LinkedIn Mastodon
Tags: cloud-saml-sso-single-sign-on-login, cloudinfrastructureservices, CVE, cve-2025-7040, OSINT, threatintel

Post Navigation

Previous Sainsbury’s Eyes Up Shoplifters With Live Facial Recognition

Search

SUPPORT THE WEBSITE



OFFICIAL MERCH STORE


Recommended eBook



Tags

#threatintel #security #osint 8base akira Black Basta bug bounty Bypass Security cisa CobaltStrikeBeaconDetected CONFIRM Cross-Site Scripting Cross Site Scripting CVE cybersecurity Cybersecurity dark web Dark Web data breach Data Manipulation Denial of Service exploit Gain Access Gain Privileges hacking HaveIBeenPwnedLatestBreaches HIBP hunters international Lockbit 2.0 lockbit 3.0 malware MISC Obtain Information OSINT patch play ransomware ransomhub ransomware Security Sliver C2 threatintel tools tor TroyHunt US-CERT Vendor Advisory vulnerability

You may have missed

image
  • Vulnerabilities

CVE Alert: CVE-2025-9515 – mondula2016 – Multi Step Form

September 6, 2025
image
  • Vulnerabilities

CVE Alert: CVE-2025-7366 – sizam – REHub – Price Comparison, Multi Vendor Marketplace WordPress Theme

September 6, 2025
image
  • Vulnerabilities

CVE Alert: CVE-2025-7040 – cloudinfrastructureservices – Cloud SAML SSO – Single Sign On Login

September 6, 2025
8a06d59ea15366c0e69aea98799ef3d6519032c0da27939e2b60993b32c316c5
  • News

Sainsbury’s Eyes Up Shoplifters With Live Facial Recognition

September 6, 2025
f4bbe270f72217d29b88d4d6a1d849ed96b19a5c334d87503496bd1e0dbd7c9f
  • News

Sap Splashes €20b On Euro Sovereign Cloud Push

September 6, 2025
Copyright © All rights reserved. | CoverNews by AF themes.
pixel