HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Auth Bypass (CVE‑2026‑61979 & CVE‑2026‑15981) in miniOrange SAML WordPress Plugin Exploited in the Wild

Two high‑severity authentication bypass flaws in the miniOrange SAML WordPress plugin are actively exploited, allowing unauthenticated attackers to assume any admin account. The issue highlights the need for robust SOC 2 access‑control monitoring and evidence of timely remediation.

LiveThreat™ Intelligence · 📅 August 25, 2026· 📰 securityaffairs.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
5 recommended
📰
Source
securityaffairs.com

Critical Auth Bypass (CVE‑2026‑61979 & CVE‑2026‑15981) in miniOrange SAML WordPress Plugin Exploited in the Wild

What It Is – The miniOrange SAML 2.0 Single Sign‑On plugin for WordPress contains two independent authentication‑bypass flaws. Both receive a CVSS 9.8 score and allow an unauthenticated attacker to forge a SAML response and gain admin‑level access to /wp‑admin.

Exploitability – Active exploitation has been observed in the wild. No public patch existed for the paid editions when the first advisory was published; attackers could weaponize the bugs immediately.

Affected Products – miniOrange SAML WordPress plugin (slug miniorange-saml-20-single-sign-on). All seven editions (Free, Premium, Standard, VIP 32.x, VIP 35.x, etc.) are vulnerable; only the free edition received an early advisory.

Why It Matters for Compliance & Audit Readiness

  • SOC 2 Access‑Control (CC6.1) coverage – Unauthenticated SAML response forgery defeats logical access controls, a core SOC 2 criterion.
  • Continuous control monitoring – The multi‑edition distribution makes inventory and patch‑status tracking difficult; auditors will look for evidence you maintain an up‑to‑date asset register.
  • Defensible audit trail – Demonstrating timely detection, patching, and privileged‑session logging is essential to prove “reasonable security” under SOC 2.

Recommended Actions

  • Immediately apply the vendor’s manual patch to all paid editions of the plugin.
  • Rotate all WordPress admin credentials and enforce MFA for privileged accounts.
  • Enable SAML response validation logging and integrate with a SIEM for real‑time alerting.
  • Update your asset inventory to list each miniOrange edition separately and map the vulnerability to SOC 2 CC6.1.
  • Capture patch‑deployment evidence (e.g., change‑control tickets, logs) for audit readiness.

Source: Security Affairs

📰 Original Source
https://securityaffairs.com/197815/security/two-cvss-9-8-auth-bypasses-in-miniorange-saml-wordpress-plugin-were-exploited-before-any-database-even-listed-the-paid-editions-as-vulnerable.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your SOC 2 posture defensible.

See where you'd stand with Verisq AI Trust Operations →