Hackers target WordPress sites in miniOrange auth bypass attacks

By George Bailey   Published: 08/24/26   3 min read
Hackers target WordPress sites in miniOrange auth bypass attacks

What Attackers Are Exploiting

BleepingComputer says attackers are targeting two critical flaws in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. The vulnerable path lets an attacker forge SAML responses and authenticate as an administrator without holding the legitimate user's identity.

The key point is not just that there are two CVEs. It is that the flaws can be chained in a way that breaks the trust site owners place in their external identity provider and the SAML assertions crossing that boundary.

Why This Is Worse Than A Normal Plugin Bug

When a plugin bug lands on the authentication path, the blast radius is larger than a typical WordPress issue. A forged admin session can mean new users, modified content, added backdoors, changed plugins, and abuse of the site's trust with readers, customers, or internal staff.

BleepingComputer also notes that both free and paid editions were affected, with reports that some paid users did not receive update warnings. That makes inventory and version verification more important than assuming the vendor-notification path reached everyone who needed it.

Why Public PoC Plus Live Scanning Changes The Timeline

This is no longer a quiet patch story. The source reporting says proof-of-concept details are public and exploitation attempts are already being observed in the wild, which compresses the response window sharply for exposed or neglected WordPress properties.

That matters because WordPress environments often live outside the cleanest enterprise ownership model. Marketing sites, microsites, acquired properties, and agency-managed builds can all carry the same vulnerable plugin while sitting outside the most disciplined patch flow.

What Teams Should Do Next

Treat this as an authentication-boundary review plus a compromise check.

Source Context

CyberExperts used BleepingComputer's reporting as the primary source and kept the coverage anchored to the operational details that matter: active exploitation, the SAML-forgery angle, the impact on both free and paid editions, and the need to check for silent administrative takeover rather than just patch and move on.

Related In The Daily Brief

See this item in The 5-Minute Cyber Brief

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.

Keep Reading