miniOrange SAML WordPress Flaws Under Active Exploit
Two authentication bypass flaws in the miniOrange SAML 2.0 SSO plugin are being actively exploited for WordPress admin takeover. Update immediately.

Exploitation attempts confirmed. Threat actors are actively targeting two unauthenticated authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, per reporting from SecurityWeek and The Hacker News (August 25, 2026).
The flaws
Two separate authentication bypasses in Xecurify’s miniOrange SAML plugin, both unauthenticated:
- CVE-2026-15981 — CVSS 9.8, Critical. Allows an unauthenticated attacker to sign in as any WordPress user, including site administrators.
- CVE-2026-61979 — CVSS 8.1, High. A second authentication bypass in the same plugin via a distinct attack path.
The plugin provides SAML-based single sign-on and is commonly deployed on corporate, educational, and government WordPress installations.
What attackers are doing
Observed: exploitation attempts targeting both CVEs. Successful exploitation grants full administrative control of the WordPress installation — including user account creation, plugin installation, and file system access via the built-in theme and plugin editors. Creating a rogue administrator account is the standard post-exploitation move.
Confidence: active exploitation attempts confirmed per SecurityWeek and The Hacker News reporting. The breadth of confirmed successful compromise has not yet been publicly quantified.
What to do now
Update the miniOrange SAML 2.0 Single Sign On plugin immediately. Go to Plugins → Updates in your WordPress dashboard.
If you cannot update right now: deactivate the plugin. An inactive plugin cannot be exploited through its SAML authentication flow.
After patching:
- Audit your administrator accounts for unfamiliar additions
- Review recent admin-level login events in your logs
- Rotate credentials for any accounts that may have been active during the exposure window
Context
This continues a pattern of WordPress plugin authentication bypasses being weaponized within days of disclosure. Earlier this month: the Forminator plugin RCE flaw affecting 600,000 sites, critical vulnerabilities in Pods and Link Library, and the multi-plugin auth bypass wave from August 15. WordPress’s scale makes plugin vulnerabilities a consistent high-value attack surface — and authentication bypasses in particular get tested fast once CVE IDs are public.
Advisory links: CVE-2026-15981 at NVD | CVE-2026-61979 at NVD
- [ CRITICAL ]CVE-2026-15981miniOrange SAML 2.0 SSO — Unauthenticated Authentication Bypass
- [ HIGH ]CVE-2026-61979miniOrange SAML 2.0 SSO — Second Authentication Bypass (High)
Found this useful? Share it.


