As cited
Copy frozen at (site build).
vulnerabilities
One slug, seven editions: the miniOrange SAML SSO bug that let anyone log in as your WordPress admin
The miniOrange SAML 2.0 Single Sign On WordPress plugin contained two critical unauthenticated authentication bypasses (CVE-2026-61979 and CVE-2026-15981) that allowed attackers to forge SAML assertions and gain administrator access. The plugin ships under a single WordPress slug but contains seven independently versioned editions, and public security advisories only covered the free edition, leaving six paid editions silently patched without public documentation. As a result, vulnerability databases incorrectly reported paid-edition installations as unaffected while they remained vulnerable, and affected sites received no update prompts in their WordPress dashboards.
Why it matters: WordPress administrators running any of the six paid editions of this plugin between August 16 and August 18, 2026 were vulnerable to unauthenticated admin account compromise with no visible warning from their dashboard or security tools, and must manually upgrade or apply hotfixes to remediate.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
One slug, seven editions: the miniOrange SAML SSO bug that let anyone log in as your WordPress admin
The miniOrange SAML 2.0 Single Sign On WordPress plugin contained two critical unauthenticated authentication bypasses (CVE-2026-61979 and CVE-2026-15981) that allowed attackers to forge SAML assertions and gain administrator access. The plugin ships under a single WordPress slug but contains seven independently versioned editions, and public security advisories only covered the free edition, leaving six paid editions silently patched without public documentation. As a result, vulnerability databases incorrectly reported paid-edition installations as unaffected while they remained vulnerable, and affected sites received no update prompts in their WordPress dashboards.
Why it matters: WordPress administrators running any of the six paid editions of this plugin between August 16 and August 18, 2026 were vulnerable to unauthenticated admin account compromise with no visible warning from their dashboard or security tools, and must manually upgrade or apply hotfixes to remediate.
- Source published
- First seen by Cybersecurity Tracker