Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Auth Bypass (CVE‑2026‑61979 & CVE‑2026‑15981) in miniOrange SAML WordPress Plugin Exploited in the Wild

Two high‑severity authentication bypass flaws in the miniOrange SAML WordPress plugin are actively exploited, allowing unauthenticated attackers to assume any admin account. The issue highlights the need for robust SOC 2 access‑control monitoring and evidence of timely remediation.

LiveThreat™ Intelligence · 📅 August 25, 2026· 📰 securityaffairs.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
5 recommended
📰
Source
securityaffairs.com

Critical Auth Bypass (CVE‑2026‑61979 & CVE‑2026‑15981) in miniOrange SAML WordPress Plugin Exploited in the Wild

What It Is – The miniOrange SAML 2.0 Single Sign‑On plugin for WordPress contains two independent authentication‑bypass flaws. Both receive a CVSS 9.8 score and allow an unauthenticated attacker to forge a SAML response and gain admin‑level access to /wp‑admin.

Exploitability – Active exploitation has been observed in the wild. No public patch existed for the paid editions when the first advisory was published; attackers could weaponize the bugs immediately.

Affected Products – miniOrange SAML WordPress plugin (slug miniorange-saml-20-single-sign-on). All seven editions (Free, Premium, Standard, VIP 32.x, VIP 35.x, etc.) are vulnerable; only the free edition received an early advisory.

Why It Matters for Compliance & Audit Readiness

  • SOC 2 Access‑Control (CC6.1) coverage – Unauthenticated SAML response forgery defeats logical access controls, a core SOC 2 criterion.
  • Continuous control monitoring – The multi‑edition distribution makes inventory and patch‑status tracking difficult; auditors will look for evidence you maintain an up‑to‑date asset register.
  • Defensible audit trail – Demonstrating timely detection, patching, and privileged‑session logging is essential to prove “reasonable security” under SOC 2.

Recommended Actions

  • Immediately apply the vendor’s manual patch to all paid editions of the plugin.
  • Rotate all WordPress admin credentials and enforce MFA for privileged accounts.
  • Enable SAML response validation logging and integrate with a SIEM for real‑time alerting.
  • Update your asset inventory to list each miniOrange edition separately and map the vulnerability to SOC 2 CC6.1.
  • Capture patch‑deployment evidence (e.g., change‑control tickets, logs) for audit readiness.

Source: Security Affairs

📰 Original Source
https://securityaffairs.com/197815/security/two-cvss-9-8-auth-bypasses-in-miniorange-saml-wordpress-plugin-were-exploited-before-any-database-even-listed-the-paid-editions-as-vulnerable.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →