Critical Login Bypass Flaws Found in Popular WordPress SSO Plugin
Security researchers have identified two serious vulnerabilities, tracked as CVE-2026-61979 and CVE-2026-15981, affecting the MiniOrange SAML 2.0 Single Sign-On (SSO) plugin for WordPress. Both flaws allow attackers to bypass authentication controls, potentially letting them log in to affected websites without valid credentials.
WordPress powers a significant share of small business websites in Australia, and plugins like MiniOrange are commonly used to simplify login processes for staff and customers. Because SSO plugins are directly tied to how users authenticate, a bypass vulnerability in this component is particularly dangerous — it could allow attackers to impersonate legitimate users, access sensitive backend systems, or take control of the site entirely.
While full technical details of exploitation have not been disclosed, the discovery of active targeting means businesses using this plugin should treat it as an urgent priority. Website compromises can lead to data theft, defacement, or the site being used to distribute malware to visitors — all of which can damage customer trust and business reputation.