Two critical authentication bypass vulnerabilities in the miniOrange SAML Single Sign On plugin could allow unauthenticated attackers to access affected WordPress sites as existing users, including administrators.
Tracked as CVE-2026-61979 and CVE-2026-15981, the flaws carry CVSS scores of 9.8 and came under closer scrutiny after DigitalOcean detected and blocked a suspicious administrator session attempt. Patchstack later detailed how some affected paid editions were not being correctly flagged by vulnerability databases.
Complicating the issue, some affected installations were not being identified as vulnerable by security databases.
miniOrange distributes seven independently versioned editions of the SAML SSO plugin under a single WordPress plugin identifier. Public advisories initially covered only the free edition, while separately numbered paid versions could appear to vulnerability databases as already patched.
Patchstack says the six paid editions had been fixed without public security advisories or changelog entries, leaving vulnerability databases without the version information needed to flag them accurately.
Some affected users also may not see a normal update notification in the WordPress dashboard. In certain cases, moving to a patched release requires manually installing a newer plugin version.
DigitalOcean reproduced the vulnerabilities on a paid Standard edition after detecting attempted exploitation. Researchers have also observed scanning of miniOrange SSO endpoints from multiple networks, which appeared to be opportunistic rather than targeted.
The free plugin has more than 10,000 active WordPress installations, while the figure does not include its separately distributed commercial editions.
Administrators using miniOrange SAML SSO should check their exact edition and version against the patched releases rather than relying solely on dashboard or vulnerability-database alerts.

Leave a Reply