miniOrange SAML SSO Plugin Authentication Bypass Exploitation
First seen Aug 25, 2026 · Updated Aug 25, 2026
Attackers are actively exploiting two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, allowing forgery of SAML responses to gain unauthorized administrator access. Sites running vulnerable versions of the plugin are at immediate risk of full site takeover.
Technical Analysis
The vulnerabilities reside in the miniOrange SAML 2.0 Single Sign On plugin for WordPress and allow attackers to forge SAML responses, bypassing authentication checks to log in as an administrator without valid credentials. This class of flaw typically stems from improper validation of SAML assertion signatures or missing verification of the response issuer, enabling attackers to craft malicious XML payloads that the plugin trusts. Exploitation grants full administrative control over the WordPress site, which can lead to backdoor installation, malicious plugin uploads, and content manipulation. Organizations that expose WordPress-based dashboards, documentation sites, or RAG data ingestion front-ends tied to AI agent workflows could see attacker-controlled content injected into pages later scraped or ingested by agents, or have API keys and credentials stored in the WP environment exposed via admin-level compromise.
Affected Systems
WordPress sites running vulnerable versions of the miniOrange SAML 2.0 Single Sign On / SP plugin; specific patched version numbers not disclosed in source data
Indicators of Compromise
- Not disclosed in source reporting
Remediation Steps
- 1
Update the plugin
Immediately update the miniOrange SAML 2.0 Single Sign On plugin to the latest patched version provided by the vendor.
- 2
Audit admin accounts
Review WordPress administrator accounts for unauthorized additions or privilege changes.
- 3
Review SAML configuration
Verify SAML response signature validation and issuer checks are properly enforced; disable SSO if patching is not immediately possible.
- 4
Rotate credentials and keys
Rotate WordPress admin credentials, API keys, and any secrets stored within the CMS environment in case of compromise.
- 5
Monitor logs
Inspect authentication and access logs for anomalous admin logins or SAML response anomalies.
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.