If your business runs a WordPress website and uses a plugin called miniOrange SAML Single Sign On to manage how users log in, this week's tip requires your attention today. Active attacks are underway, and many site owners who are at risk have no idea because the warning from the vendor never reached them.
What the miniOrange Plugin Does — and What Went Wrong
miniOrange SAML SSO is a popular WordPress plugin used by tens of thousands of websites. It allows users to log into a WordPress site using their existing corporate credentials from platforms like Microsoft Entra ID, Okta, or Google Workspace, rather than maintaining a separate WordPress username and password. For businesses managing staff access to a WordPress-powered site or intranet, it is a common and convenient solution.
Two critical security vulnerabilities were discovered in this plugin, tracked as CVE-2026-61979 and CVE-2026-15981. When chained together, they allow an attacker to completely bypass the login process and gain administrator-level access to the WordPress site without valid credentials. No username. No password. Just a forged authentication request that the vulnerable plugin accepts as legitimate.
In plain terms, an attacker can walk through the front door of a WordPress site as if they are an administrator, without ever being one.
The vulnerabilities were fixed and disclosed in July 2026. The problem is that the vendor's public advisory only mentioned the free version of the plugin. Six paid editions, used by businesses and organizations that paid for expanded features, received no public warning at all, even though patches were available for those versions too. Many paid users saw nothing in their WordPress dashboard telling them an update was needed, because WordPress does not automatically display security alerts for premium plugins the same way it does for free ones.
That gap between disclosure and awareness is exactly what attackers moved into.
What Is Happening Right Now
On August 16th, a confirmed attack was detected when DigitalOcean flagged an anomalous WordPress administrator session originating outside its trusted network. Investigation revealed that attackers had chained the two vulnerabilities to obtain a full admin session cookie using the Standard edition of the plugin in version 16.1.9.
Active scanning and exploitation attempts are now underway from multiple IP addresses across Europe, Africa, and the United States. A working proof-of-concept exploit targeting the free edition is also publicly available, which means the pace of attacks could increase at any time. Any unpatched site running any edition of the miniOrange SAML SSO plugin is a potential target.
What an Attacker Can Do With Admin Access to Your WordPress Site
Full administrator access to a WordPress site is not a minor problem. An attacker with that access can install malicious plugins or code, redirect visitors to harmful websites, steal form submissions and customer data, lock out legitimate administrators, deface or take down the site entirely, and use the site's infrastructure to attack others. For a business that relies on its website for customer communication, lead generation, or e-commerce, any of those outcomes can cause serious operational and reputational damage.
What Your Team Should Do Right Now
- If your website uses the miniOrange SAML SSO plugin in any edition, check the version currently installed and compare it to the patched versions listed below. Because WordPress may not show an update notification for paid editions, you will need to check this manually through your plugin settings or your vendor account.
- The patched versions that address both vulnerabilities are as follows. Free single site: version 5.4.5. Premium single site: version 13.0.4. Standard single site: version 17.06. Premium, Enterprise, and All-Inclusive multisite: version 20.2.8. Enterprise and All-Inclusive single site: version 26.0.3. VIP single site: version 32.0.8. VIP multisite: version 35.0.7.
- If you are running any version older than the ones listed above, update immediately through your miniOrange account or vendor portal.
- If you are unsure whether your site uses this plugin, ask your web developer or IT provider to check. The plugin may have been installed during an earlier configuration and may not be front of mind for day-to-day site management.
- After updating, review your WordPress administrator accounts for any additions you do not recognize. If an attacker gained access before the update, they may have created a backdoor account to maintain future access.
- As a general practice, consider whether single sign-on plugins on your WordPress site are configured with the minimum permissions necessary, and whether administrator access to your site is protected by multi-factor authentication.
The Bottom Line
A critical vulnerability in a widely used WordPress plugin is being actively exploited today, and the businesses most at risk are the ones who never received a clear warning that they needed to act. If your site uses miniOrange SAML SSO in any edition, manual verification and immediate updating is the only safe course of action.
Have questions about your WordPress site's security or whether your plugins are up to date? Reach out to us — we are here to help.
