miniOrange SAML 2.0 SSO — Second Authentication Bypass (High)
High-severity auth bypass in miniOrange SAML 2.0 SSO for WordPress; being exploited alongside critical CVE-2026-15981 in active attack campaigns.
- Vendor
- Xecurify
- Product
- miniOrange SAML 2.0 Single Sign On
- CVSS
- 8.1
- EPSS (exploit probability)
- N/A
- Status
- exploited-in-wild
- Published
Second unauthenticated authentication bypass in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, reported alongside CVE-2026-15981 (CVSS 9.8, Critical). Both vulnerabilities affect the same plugin and are being actively exploited in tandem.
Impact: Authentication bypass allowing access as arbitrary WordPress users. Combined with CVE-2026-15981, attackers have two separate mechanisms to achieve unauthorized access; the pair increases the attack surface and complicates any partial mitigations.
Affected product: Xecurify’s miniOrange SAML 2.0 Single Sign On plugin for WordPress. Consult the vendor advisory for affected version ranges.
Exploitation status: Active exploitation attempts confirmed per SecurityWeek and The Hacker News reporting (August 25, 2026).
Patch: Update the plugin immediately via Plugins → Updates in the WordPress dashboard. If patching cannot happen immediately, deactivate the plugin.
Post-patch steps: Audit administrator account list. Review recent login logs for unauthorized admin-level sessions.
See full coverage: miniOrange SAML WordPress Flaws Under Active Exploit
