The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provisioned users.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "2.2.0"
}
]
}