Security News

Critical Login Bypass Flaws Found in Popular WordPress SSO Plugin

Security Week · 25 Aug 2026
Key Takeaway If your WordPress site uses the MiniOrange SAML SSO plugin, check for and apply the latest security update immediately, or disable the plugin until a patch is confirmed available.

Security researchers have identified two serious vulnerabilities, tracked as CVE-2026-61979 and CVE-2026-15981, affecting the MiniOrange SAML 2.0 Single Sign-On (SSO) plugin for WordPress. Both flaws allow attackers to bypass authentication controls, potentially letting them log in to affected websites without valid credentials.

WordPress powers a significant share of small business websites in Australia, and plugins like MiniOrange are commonly used to simplify login processes for staff and customers. Because SSO plugins are directly tied to how users authenticate, a bypass vulnerability in this component is particularly dangerous — it could allow attackers to impersonate legitimate users, access sensitive backend systems, or take control of the site entirely.

While full technical details of exploitation have not been disclosed, the discovery of active targeting means businesses using this plugin should treat it as an urgent priority. Website compromises can lead to data theft, defacement, or the site being used to distribute malware to visitors — all of which can damage customer trust and business reputation.

Summarised by CISO AI from Security Week. We link back to every original so you can read it yourself.