Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-15981

miniOrange SAML 2.0 SSO — Unauthenticated Authentication Bypass

Critical auth bypass in miniOrange SAML 2.0 SSO for WordPress lets unauthenticated attackers sign in as any user including admins. Exploitation confirmed.

cat cve-2026-15981.json
Vendor
Xecurify
Product
miniOrange SAML 2.0 Single Sign On
CVSS
9.8
EPSS (exploit probability)
N/A
Status
exploited-in-wild
Published

Unauthenticated authentication bypass in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. The flaw allows an attacker without valid credentials to authenticate as any WordPress user — including administrators — through a logic error in the plugin’s SAML authentication flow.

Impact: Full WordPress administrative control. An attacker who signs in as an administrator can create additional rogue administrator accounts, install malicious plugins, and access the file system via the built-in theme/plugin editors.

Affected product: Xecurify’s miniOrange SAML 2.0 Single Sign On plugin for WordPress. Commonly deployed on corporate, educational, and government WordPress installations using SAML-based SSO. Consult the vendor advisory for affected version ranges.

Exploitation status: Active exploitation attempts confirmed. Attackers are targeting this CVE alongside CVE-2026-61979 (CVSS 8.1), a second authentication bypass in the same plugin.

Patch: Update the plugin via your WordPress dashboard (Plugins → Updates). If immediate update is not possible, deactivate the plugin until patching can be completed.

Post-patch steps: Audit administrator accounts for unfamiliar additions. Review recent admin-level login activity for signs of unauthorized access. Rotate credentials for any accounts that may have been exposed.

See full coverage: miniOrange SAML WordPress Flaws Under Active Exploit