Introduction
Two critical vulnerabilities in the miniOrange SAML 2.0 Single Sign-On plugin, tracked as CVE-2026-61979 and CVE-2026-15981 (CVSS 9.8), let an unauthenticated attacker forge SAML assertions and log in as any existing user — including a site administrator — without ever knowing a password.
This is the third critical miniOrange plugin vulnerability covered on this page this season, after the OAuth Single Sign-On and Social Login and Register flaws. If your site uses any miniOrange authentication product, this is no longer a coincidence worth ignoring — it’s a pattern.
What You Should Do Right Now
- Check exactly which miniOrange plugin(s) you have installed under Plugins in wp-admin. SAML 2.0 SSO, OAuth SSO, and Social Login and Register are three separate products, each needing its own check and update.
- Back up your site immediately before applying any update.
- Update to the patched version as soon as it’s confirmed available.
- Review your admin user list and recent login activity for anything unfamiliar, especially logins that bypass your normal SSO flow.
Why SAML Assertion Forgery Is Especially Serious
SAML-based single sign-on is often deployed specifically because it’s considered a more secure, enterprise-grade login method than plain WordPress passwords. A flaw that lets an attacker forge the very assertions SAML relies on undermines that entire premise — the “more secure” login path becomes the weakest one. Sites that adopted SAML SSO for exactly this reason are now facing the opposite of what they signed up for.
FAQ
Does this affect the other miniOrange plugins too?
This specific pair of CVEs is in the SAML 2.0 SSO product. However, given three separate miniOrange plugins have had critical flaws recently, check your entire miniOrange plugin list regardless of which one made headlines this time.
How would I know if my site was already compromised?
Check for administrator accounts you didn’t create, and review login activity for sessions that didn’t go through your expected SSO provider.
Is there a workaround if I can’t update right away?
Consider temporarily disabling SAML-based login and falling back to standard WordPress authentication with strong passwords and two-factor authentication until the plugin is patched.
Conclusion
A third critical miniOrange authentication flaw in one season is a strong signal to audit every miniOrange product on your site, not just patch the one in this headline.
A safe rollback point for every update
Nota Backup & Restore keeps automatic, off-site backups so you can update with confidence and recover fast if something’s already wrong. Start your 14-day free trial — no credit card required.
