CVE-2026-61979critical
Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable
Two critical authentication bypass vulnerabilities (CVSS 9.8) in the miniOrange SAML 2.0 Single Sign On WordPress plugin have been actively exploited. These flaws allow unauthenticated attackers to forge SAML responses and gain administrative access. The vulnerabilities were particularly insidious because they affected paid editions of the plugin, which were not listed in public vulnerability databases and did not trigger automatic updates, leaving administrators unaware of their exposure.