WordPress site operators using the miniOrange SAML 2.0 Single Sign On (SSO) plugin are facing active exploitation attempts targeting two critical authentication bypass vulnerabilities. These flaws allow attackers to forge SAML responses, enabling unauthorized administrative access without valid credentials.
What happened
Hackers have begun scanning for vulnerable installations of the miniOrange plugin, which provides SAML-based SSO functionality for WordPress. The vulnerabilities permit authentication bypass by manipulating SAML assertions, effectively allowing attackers to impersonate legitimate users—including administrators. The source did not specify how many sites have been compromised or whether patches are available, but confirmed the attacks are ongoing.
The plugin is used by organizations to centralize authentication across WordPress and other enterprise applications. Compromised admin access could lead to full site takeover, data exfiltration, or deployment of malicious payloads such as backdoors or phishing pages.
What we don’t know yet
Details remain limited on the scope of the attacks. It is unclear whether miniOrange has released a fix, how many sites are affected, or if specific industries or regions are being targeted. The source also did not confirm whether exploit code is publicly available, though active scanning suggests attackers are already weaponizing the vulnerabilities.
Companies mentioned
Automated pipeline · Security
Synthesized from 1 industry feed on 24 Aug 2026. Passed independent editor verification (score 85/100) before publication. Style guide v1.4.
Sources
Decision trail
- Checking for duplicates — Deduped batch of 1 candidates
- Checking for duplicates — Failed no verdict returned
- Checking for duplicates — Deduped batch of 1 candidates
- Checking for duplicates — New story No existing article covers this specific WordPress plugin vulnerability.
- Checking for duplicates — New story pre_write:; No previously published or in-pipeline article covers this specific miniOrange SAML 2.0 WordPress plugin vulnerability.
- Writing the article — Brief only thin sources; quick-read mode
- Writing the article — Draft created article_id=465 slug=wordpress-sites-hit-by-miniorange-saml-auth-bypass-attacks quick_read=1
-
Editor review — Approved
- Score: 85/100
- Factual grounding: The draft states 'The source did not specify how many sites have been compromised or whether patches are available,' but the source text does not explicitly confirm that attacks are 'ongoing'—only that hackers are 'attempting to exploit.' The term 'ongoing' implies sustained activity not directly supported by the source.
- Style compliance: The standfirst ('Hackers exploit two critical flaws in a WordPress SSO plugin to gain admin access') slightly editorializes by stating 'exploit' as a fact, while the source only confirms 'attempting to exploit.' Rephrase to match source certainty (e.g., 'Hackers attempt to exploit...').
- Quote integrity: No blockquotes are used, but the draft paraphrases source content without explicit attribution. While not a blockquote violation, ensure all claims are clearly traceable to the source (e.g., 'The source confirmed...').
- Generating reader Q&A — Generated 3 items
- Assigning hero image — Reused library image reused image #155
- Linking related stories — Linked 0 relations from 400 candidates
- Publishing — Published wordpress-sites-hit-by-miniorange-saml-auth-bypass-attacks
- Mastodon — Posted https://mstdn.social/@hostingpaper/117152702887471948

Discussion · coming soon
Be the first to join the thread when community discussion launches.