miniOrange SAML 2.0 SSO — Unauthenticated Authentication Bypass
Critical auth bypass in miniOrange SAML 2.0 SSO for WordPress lets unauthenticated attackers sign in as any user including admins. Exploitation confirmed.
- Vendor
- Xecurify
- Product
- miniOrange SAML 2.0 Single Sign On
- CVSS
- 9.8
- EPSS (exploit probability)
- N/A
- Status
- exploited-in-wild
- Published
Unauthenticated authentication bypass in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. The flaw allows an attacker without valid credentials to authenticate as any WordPress user — including administrators — through a logic error in the plugin’s SAML authentication flow.
Impact: Full WordPress administrative control. An attacker who signs in as an administrator can create additional rogue administrator accounts, install malicious plugins, and access the file system via the built-in theme/plugin editors.
Affected product: Xecurify’s miniOrange SAML 2.0 Single Sign On plugin for WordPress. Commonly deployed on corporate, educational, and government WordPress installations using SAML-based SSO. Consult the vendor advisory for affected version ranges.
Exploitation status: Active exploitation attempts confirmed. Attackers are targeting this CVE alongside CVE-2026-61979 (CVSS 8.1), a second authentication bypass in the same plugin.
Patch: Update the plugin via your WordPress dashboard (Plugins → Updates). If immediate update is not possible, deactivate the plugin until patching can be completed.
Post-patch steps: Audit administrator accounts for unfamiliar additions. Review recent admin-level login activity for signs of unauthorized access. Rotate credentials for any accounts that may have been exposed.
See full coverage: miniOrange SAML WordPress Flaws Under Active Exploit
