Critical Vulnerability Information Vulnerability Overview CVE: CVE-2015-6398 CVSS Score: 5.3 (Medium) Public Disclosure Date: June 11, 2015 Last Updated: June 12, 2015 Researcher: Israel Hale (Palo) - France Description The WordPress Single Sign-On (SSO) plugin, in all versions, is affected by an unauthorized access issue due to a misconfigured feature. This allows unauthorized attackers to extract sensitive data, including site content. Affected Packages Remediation Recommendation Upgrade to version 40.5.4 or later.