Critical WordPress SAML SSO Flaws Enable Unauthenticated Admin Account Takeover
Brief
Two critical vulnerabilities in the miniOrange SAML 2.0 Single Sign-On WordPress plugin could allow unauthenticated attackers to forge SAML assertions and access /wp-admin as any existing account, including administrators.
The flaws, tracked as CVE-2026-61979 and CVE-2026-15981, carry a CVSS score of 9.8 and have reportedly been targeted by opportunistic scanning activity.
DigitalOcean’s security team detected and blocked an anomalous WordPress administrator session attempt on its infrastructure, and then reproduced both bypasses in miniOrange’s Standard edition, version 16.
- 9.
Critical WordPress SAML SSO Flaws
Patchstack coordinated vendor follow-up and expanded its vulnerability database coverage after discovering that the plugin’s distribution model obscured exposure across paid editions.
CVE-2026-61979 stems from signature-algorithm confusion.
