Silent Patch Leaves WordPress Admins Exposed
Critical MiniOrange SAML SSO flaws exploited in wild; silent patch raises risk for WordPress sites.
Attackers are actively probing WordPress websites that run a widely used single sign-on plugin, leveraging two recently fixed critical vulnerabilities that could let them slip into any account—including administrator access. The catch: the plugin's developer patched the flaws without clearly warning users, and in many cases, without alerting them at all.
Two Flaws, One Login Bypass
DigitalOcean and security firm Patchstack identified the vulnerabilities, tracked as CVE-2026-61979 and CVE-2026-15981, in the MiniOrange SAML 2.0 Single Sign-On (SSO) plugin. According to the analysis, they are critical authentication bypasses that allow an attacker to log in as any WordPress user, including administrators.
The plugin's free edition alone is installed on more than 10,000 WordPress sites. Patchstack notes that paid and enterprise versions exist, but usage statistics for those are not available.
Opportunistic Exploitation in the Wild
Patchstack described the observed attacks as opportunistic rather than a targeted campaign. The threat actors appear to be hammering every site that has the plugin installed, without discriminating between different editions or versions.
“Whoever is running this appears to be throwing the exploit at every site with the plugin installed without checking which edition or version is behind it,” Patchstack warned. “This is exactly the behavior that makes the silent-patch situation dangerous. The attacker does not need to know which edition you run, you do.”
Patches Applied, But Kept Quiet
The developer has patched all affected versions of the MiniOrange SAML 2.0 SSO plugin. However, for the free edition, the advisory mentions the fix in version 5.4.5 but labels it as a bugfix rather than a security patch. Users of paid editions have not received any notification about the vulnerabilities.
Compounding the issue, the paid editions use a different versioning system, making it hard for users to know if their installation is patched. The only way to be sure is to manually update the plugin.
Key Facts and Figures
- Two critical vulnerabilities: CVE-2026-61979 and CVE-2026-15981
- Free edition of the plugin is installed on over 10,000 WordPress sites
- Free edition fix in version 5.4.5, listed as a bugfix not a security patch
What It Means for Your Site
For WordPress administrators using the MiniOrange SAML 2.0 SSO plugin, the lack of clear patching guidance creates a dangerous blind spot. Even if a site is running the latest version, it's impossible to verify without manually checking the version number against the developer's patches.
Given the active exploitation, admins should prioritize updating the plugin immediately, even if no official security notice was received. The silent-patch approach leaves defenders in the dark, while attackers are already scanning for vulnerable sites.
The situation underscores the importance of proactive patching and monitoring for WordPress plugins, especially those that handle authentication. A vulnerability like this can hand over the keys to the entire site, and without clear communication from developers, users are left guessing whether they are safe.
Sources
- SecurityWeek Original source
Continue Reading
LACMA Breach Exposed Sensitive Data
LACMA's 2025 breach exposed social security and medical data; notifications sent.
NVIDIA AI Agent Flaw Opens Door to Model Poisoning
A NemoClaw weakness lets a webpage hijack local Ollama and inject persistent instructions into models.
Real-time phishing platform steers attacks
A phishing platform gives attackers live control over victim sessions, adapting prompts as credentials are harvested.