miniOrange SAML Flaws Hand Attackers WordPress Admin

Attackers are actively probing two critical authentication-bypass flaws in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, tracked as CVE-2026-61979 and CVE-2026-15981. BleepingComputer says the bugs let a forged SAML response pass as legitimate and land the attacker in the site as an administrator. The break is in the trust check. The plugin is supposed to accept only login assertions from the identity provider, but a fake response can be accepted as valid, so WordPress treats the attacker as already authenticated with admin rights. That means the problem is site takeover, not just a bad user session or a stolen password. For any site that uses SAML for staff or admin access, the exposure sits in the login path itself: if that trust boundary fails, password resets and MFA checks do not address the entry point. What remains after patching is the question of whether any forged session was already accepted before the fix landed.

Part of the PlainSec briefing for 2026-08-25

Editions

Sources