CVE Tools

One slug, seven editions: the miniOrange SAML SSO bug that let anyone log in as your WordPress admin

PatchstackBy Dave Jong

Reported exploitedminiOrange

Our summary

DigitalOcean's security team detected active exploitation of two critical authentication bypass vulnerabilities, CVE-2026-61979 and CVE-2026-15981, within the miniOrange SAML 2.0 Single Sign On WordPress plugin. These flaws allow unauthenticated attackers to forge SAML assertions and assume control of administrator accounts, posing a severe risk to site integrity.

A significant portion of affected installations remained unaware of the threat because the plugin ships seven distinct commercial editions under a single WordPress slug, with paid versions patched silently without public advisories or database entries. To mitigate this immediate risk, administrators must manually verify their specific edition version and apply the relevant vendor fix or implement the temporary hotfixes documented by DigitalOcean.

Read at Patchstack

Patchstack publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store