WordPress websites are currently facing security threats due to two critical vulnerabilities found in the MiniOrange SAML 2.0 Single Sign-On plugin. The vulnerabilities, identified as CVE-2026-61979 and CVE-2026-15981, allow attackers to bypass authentication and potentially log in as any user, including administrators. Though the plugin's free version, installed on over 10,000 sites, has an advisory for the fix in version 5.4.5, it is only mentioned as a bugfix rather than a security update. Paid versions lack a clear notification system, forcing users to manually check and update their plugins.
DigitalOcean and Patchstack, the security firm that identified the vulnerabilities, report that attackers are exploiting these flaws through opportunistic attacks. This means they are attempting to breach any site using the plugin without concern for which version or edition is installed. Patchstack warns that this creates a dangerous situation, as attackers do not need to know the specific version to exploit the vulnerabilities.
Despite the availability of patches, the absence of adequate communication from the plugin developer about the risks and the necessary updates leaves many sites vulnerable. Security teams need to be proactive in ensuring their systems are secure, especially in the absence of clear guidance from developers on these critical issues.


