MiniOrange SAML Flaws Allow Admin Logins on WordPress

Two patched vulnerabilities in the MiniOrange SAML 2.0 SSO WordPress plugin allow attackers to log in as any user, including administrators; paid users were not notified.

Attackers have been exploiting two recently patched vulnerabilities in the MiniOrange SAML 2.0 Single Sign-On (SSO) WordPress plugin-CVE-2026-61979 and CVE-2026-15981-to bypass authentication and sign in as any user, including administrators. Exploitation has been observed in the wild. The plugin’s free edition is installed on more than 10,000 WordPress sites; install figures for paid and enterprise editions are not public.

Security teams at DigitalOcean and the security firm Patchstack analyzed the flaws and described them as critical authentication bypasses. Patchstack characterized the activity as opportunistic scanning rather than a targeted campaign, with attackers probing broadly for sites that run the plugin.

Patches are available for all affected editions, but developer communications have been inconsistent. The free edition includes an advisory noting the issue was fixed in version 5.4.5, but the update is listed as a bugfix rather than a security release. Users of paid and enterprise editions were not given explicit public notifications.

Differences in versioning between the free and paid editions make it hard for administrators to tell whether a deployment is running a patched release. Site owners must manually confirm plugin versions, consult the vendor changelog or contact MiniOrange support to verify whether their specific edition contains the fixes.

Researchers recommend that hosting providers and security teams prioritize checks of SAML SSO installations, apply available updates and monitor access logs for suspicious authentication attempts. Until sites confirm updated installations, operators should assume they may be probed or attacked.

Patchstack warned: “Whoever is running this appears to be throwing the exploit at every site with the plugin installed without checking which edition or version is behind it. This is exactly the behavior that makes the silent-patch situation dangerous. The attacker does not need to know which edition you run, you do.”

Requests for comment were sent to the plugin developer; any response may clarify how fixes map across editions and how paid customers were notified.

Articles by this author