One slug, seven editions: the miniOrange SAML SSO bug that let anyone log in as your WordPress admin
Reported exploitedminiOrangeOur summary
DigitalOcean's security team detected active exploitation of two critical authentication bypass vulnerabilities, CVE-2026-61979 and CVE-2026-15981, within the miniOrange SAML 2.0 Single Sign On WordPress plugin. These flaws allow unauthenticated attackers to forge SAML assertions and assume control of administrator accounts, posing a severe risk to site integrity.
A significant portion of affected installations remained unaware of the threat because the plugin ships seven distinct commercial editions under a single WordPress slug, with paid versions patched silently without public advisories or database entries. To mitigate this immediate risk, administrators must manually verify their specific edition version and apply the relevant vendor fix or implement the temporary hotfixes documented by DigitalOcean.
Patchstack publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.