Critical Auth Bypass (CVE‑2026‑61979 & CVE‑2026‑15981) in miniOrange SAML WordPress Plugin Exploited in the Wild
What It Is – The miniOrange SAML 2.0 Single Sign‑On plugin for WordPress contains two independent authentication‑bypass flaws. Both receive a CVSS 9.8 score and allow an unauthenticated attacker to forge a SAML response and gain admin‑level access to /wp‑admin.
Exploitability – Active exploitation has been observed in the wild. No public patch existed for the paid editions when the first advisory was published; attackers could weaponize the bugs immediately.
Affected Products – miniOrange SAML WordPress plugin (slug miniorange-saml-20-single-sign-on). All seven editions (Free, Premium, Standard, VIP 32.x, VIP 35.x, etc.) are vulnerable; only the free edition received an early advisory.
Why It Matters for Compliance & Audit Readiness
- SOC 2 Access‑Control (CC6.1) coverage – Unauthenticated SAML response forgery defeats logical access controls, a core SOC 2 criterion.
- Continuous control monitoring – The multi‑edition distribution makes inventory and patch‑status tracking difficult; auditors will look for evidence you maintain an up‑to‑date asset register.
- Defensible audit trail – Demonstrating timely detection, patching, and privileged‑session logging is essential to prove “reasonable security” under SOC 2.
Recommended Actions
- Immediately apply the vendor’s manual patch to all paid editions of the plugin.
- Rotate all WordPress admin credentials and enforce MFA for privileged accounts.
- Enable SAML response validation logging and integrate with a SIEM for real‑time alerting.
- Update your asset inventory to list each miniOrange edition separately and map the vulnerability to SOC 2 CC6.1.
- Capture patch‑deployment evidence (e.g., change‑control tickets, logs) for audit readiness.
Source: Security Affairs