CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

One slug, seven editions: the miniOrange SAML SSO bug that let anyone log in as your WordPress admin

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5818

As cited

Copy frozen at (site build).

vulnerabilities

One slug, seven editions: the miniOrange SAML SSO bug that let anyone log in as your WordPress admin

The miniOrange SAML 2.0 Single Sign On WordPress plugin contained two critical unauthenticated authentication bypasses (CVE-2026-61979 and CVE-2026-15981) that allowed attackers to forge SAML assertions and gain administrator access. The plugin ships under a single WordPress slug but contains seven independently versioned editions, and public security advisories only covered the free edition, leaving six paid editions silently patched without public documentation. As a result, vulnerability databases incorrectly reported paid-edition installations as unaffected while they remained vulnerable, and affected sites received no update prompts in their WordPress dashboards.

Why it matters: WordPress administrators running any of the six paid editions of this plugin between August 16 and August 18, 2026 were vulnerable to unauthenticated admin account compromise with no visible warning from their dashboard or security tools, and must manually upgrade or apply hotfixes to remediate.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

One slug, seven editions: the miniOrange SAML SSO bug that let anyone log in as your WordPress admin

The miniOrange SAML 2.0 Single Sign On WordPress plugin contained two critical unauthenticated authentication bypasses (CVE-2026-61979 and CVE-2026-15981) that allowed attackers to forge SAML assertions and gain administrator access. The plugin ships under a single WordPress slug but contains seven independently versioned editions, and public security advisories only covered the free edition, leaving six paid editions silently patched without public documentation. As a result, vulnerability databases incorrectly reported paid-edition installations as unaffected while they remained vulnerable, and affected sites received no update prompts in their WordPress dashboards.

Why it matters: WordPress administrators running any of the six paid editions of this plugin between August 16 and August 18, 2026 were vulnerable to unauthenticated admin account compromise with no visible warning from their dashboard or security tools, and must manually upgrade or apply hotfixes to remediate.

VendorsGitHubOpenSSLWordPress
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary