Cybercriminals are actively exploiting two authentication-bypass vulnerabilities in the MiniOrange SAML 2.0 Single Sign-On plugin that allow attackers to impersonate WordPress administrators without credentials, according to a joint security analysis published August 25 by DigitalOcean and Patchstack.
TL;DR: Two critical vulnerabilities (CVE-2026-61979 and CVE-2026-15981) in the MiniOrange SAML SSO plugin enable unauthenticated attackers to gain administrator access; patches are available but were released without explicit security warnings, creating a "silent-patch scenario."
The flaws, designated CVE-2026-61979 and CVE-2026-15981, affect both free and paid versions of the plugin. The free edition is installed on more than 10,000 WordPress sites, according to the analysis. Usage metrics for paid and enterprise versions are not publicly available, complicating efforts to assess total exposure.
Critical Authentication Bypass Enables Administrator Impersonation
The vulnerabilities allow attackers to impersonate any user account, including site administrators, without requiring valid credentials, according to the joint analysis by DigitalOcean and security firm Patchstack. The flaws were classified as critical due to their potential to grant unrestricted access to sensitive data and administrative controls.
Patchstack reported that exploitation attempts appear opportunistic rather than targeted. Attackers are deploying the exploit indiscriminately against all sites running the plugin, regardless of edition or version. The firm emphasized that this broad-sweep approach increases risk exposure because users of paid versions may not be aware of the vulnerabilities.

Patches Released Without Explicit Security Warnings
Patches are available for all affected versions, but the plugin developer has not issued explicit security warnings about the risks, according to the analysis. The free edition's update to version 5.4.5 addresses the vulnerabilities but frames the changes as bugfixes rather than security patches. This presentation potentially leads users to overlook the update's urgency.
"The lack of transparency creates a 'silent-patch' scenario, where defenders remain unaware of their exposure," Patchstack stated in the analysis. The firm noted that paid editions require manual updates, increasing the likelihood of systems remaining unpatched.
The plugin developer has not publicly disclosed a timeline for when the vulnerabilities were discovered or when patches were first made available. Patchstack reported that it has contacted the developer for clarification and will update findings if additional information becomes available.
Exploitation Patterns Show Indiscriminate Targeting
Security researchers observing exploitation patterns report that threat actors are scanning for and attacking all installations of the MiniOrange SAML 2.0 SSO plugin, regardless of whether sites are running vulnerable versions. This behavior underscores the dangers of delayed or unclear communication from plugin vendors, according to Patchstack.
The combination of widespread plugin usage, active exploitation, and ambiguous patch notifications creates a persistent attack surface, according to the analysis. Organizations using the plugin are advised to verify their installation version immediately and apply available updates. Similar authentication bypass vulnerabilities have affected other WordPress plugins in recent months, exposing thousands of sites to unauthorized access.
The broader pattern of WordPress plugin vulnerabilities continues to challenge agencies managing multiple client sites, particularly when vendors do not follow standard security disclosure practices.
What This Means for Agency Owners
Agencies managing WordPress sites for clients face immediate operational tasks: audit every client site for MiniOrange SAML 2.0 SSO installations, verify plugin versions against the patched release (5.4.5 for free editions), and apply updates manually where auto-update mechanisms are disabled. The silent-patch scenario means routine plugin update workflows may miss this critical security fix if teams rely solely on security bulletins or urgent notifications from developers.
The incident highlights a structural weakness in agency workflows: third-party plugin security depends on vendor communication practices that vary widely. Agencies should implement automated plugin inventory scanning across their client portfolio and establish update protocols that do not depend on vendors flagging patches as security-related. For sites using paid or enterprise versions of MiniOrange with non-standard versioning, contact the vendor directly for version confirmation and patch availability.
The opportunistic exploitation pattern—attackers scanning all plugin installations regardless of version—means agencies cannot assume unpatched sites are safe simply because they have not yet detected compromise. WordPress sites remain high-value targets for credential theft and malware distribution, and SAML SSO plugins represent particularly sensitive infrastructure because they control authentication across multiple systems.
