York Computer logo York Computer
Managed IT & Security
Cybersecurity News

Hackers Exploiting WordPress miniOrange SSO Flaw — Silent Patches Left Scanners Blind

York Computer

Two critical authentication-bypass flaws in the miniOrange SAML 2.0 Single Sign-On plugin for WordPress are being actively exploited this week — and attackers can log in as a WordPress administrator without any credentials at all. If your business website runs WordPress and uses miniOrange to connect logins to Microsoft Entra ID, Google Workspace, Okta, or OneLogin, your site could be an open door right now. Worse, most vulnerability scanners are reporting affected sites as safe because the vendor quietly patched six of its paid editions without publishing a security advisory.

What happened

Security researchers at DigitalOcean and Patchstack disclosed two chained vulnerabilities in the miniOrange SAML SSO plugin, and attackers wasted no time weaponizing them. Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators.

The two bugs — tracked as CVE-2026-61979 and CVE-2026-15981, carry a CVSS score of 9.8 and have been linked to attempted exploitation activity in the wild. Chained together, they let an unauthenticated attacker forge a SAML login response and drop straight into the WordPress /wp-admin panel.

The miniOrange plugin is not obscure. The miniOrange SAML SSO plugin turns a WordPress site into a SAML service provider, letting users log in through corporate identity platforms such as Microsoft Entra ID, Okta, Google Workspace, or OneLogin instead of separate WordPress credentials. Created by Xecurify, miniOrange is a family of seven plugins, with a free version that has 10,000 downloads and 30,000 customers for the other six.

Why this one is nastier than a normal WordPress bug

Two details make this incident particularly dangerous for small businesses.

First, the vendor patched the paid editions silently. The public security advisories only ever covered the free edition. The six paid editions were patched with no public changelog and no advisory, so no vulnerability database listed them, and vulnerable sites were incorrectly reported as unaffected. If your web team or MSP relies on a scanner to tell them what's vulnerable, that scanner has been lying to you.

Second, the exploitation is opportunistic, not targeted. An attacker had seemingly obtained a WordPress administrator session cookie through the authentication bypass but was unable to perform administrative actions due to access restrictions to the admin panel, which were limited to a trusted network. The observed scanning originated from infrastructure in Belgium, Nigeria, Germany, and the United States, suggesting opportunistic exploitation attempts rather than a targeted campaign. Translation: attackers are spraying the exploit at every WordPress site on the internet and waiting to see which ones fall over. Small business sites are as much of a target as enterprise ones. A public proof-of-concept for the free edition is already circulating, which typically accelerates mass exploitation.

What your managed-IT provider should be doing this week

If a small business is running WordPress with any SSO plugin, the response checklist is short but not optional:

1. Identify which edition of miniOrange is installed — free or one of the six paid tiers — and manually upgrade to the patched release. A vulnerable 16.x release has no managed update prompt at all. You're on your own to manually upload the fix. 2. Restrict access to /wp-admin by IP or VPN so that even a forged session cookie can't reach the administrator panel from the open internet. 3. Review WordPress admin user accounts and active sessions for anything unfamiliar since mid-August, and force a password reset plus MFA re-enrollment for every admin. 4. Check web server logs for SAML POST requests from the IP ranges called out by researchers.

This is the kind of quiet, tedious blocking-and-tackling that separates a real managed provider from a break/fix shop. Patch management, WordPress hardening, web-application monitoring, and account-takeover response all sit inside York Computer's managed IT services — and if you already have an internal IT person handling day-to-day, this is exactly the kind of after-hours emergency where co-managed IT support earns its keep.

What York Businesses Should Do

York County small businesses — especially professional services firms, nonprofits, and manufacturers running WordPress marketing sites tied into Microsoft 365 or Google Workspace SSO — should audit their plugin list this week and confirm the miniOrange patch is applied. If you're not sure who owns your WordPress site's security posture, that ambiguity is itself the vulnerability.

Sources

Worried whether your business is exposed to this? Talk to York Computer.

Managed IT & cybersecurity for York County small businesses.

← Back to all articles