← Blog · · df00tech

WordPress miniOrange SAML SSO Plugin: Active Exploitation of Auth Bypass Flaws Enables Admin Takeover

security-news technique

According to BleepingComputer, attackers are actively attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign-On plugin for WordPress. The flaws reportedly allow an attacker to forge SAML responses, effectively letting them log in as an administrator without valid credentials.

Why It Matters

SAML SSO plugins sit directly in the authentication path, so a bypass here isn't a minor content-management issue — it's a direct route to full site takeover. Any WordPress site using the miniOrange SAML 2.0 SSO plugin for authentication is potentially exposed, and admin-level access typically enables plugin/theme installation, backdoor placement, content tampering, and pivoting to hosting infrastructure. The fact that exploitation attempts are already being observed in the wild raises urgency for affected site operators.

What Defenders Should Watch For

  • Inventory WordPress instances using the miniOrange SAML 2.0 SSO plugin and confirm patch/version status against vendor guidance as it becomes available.
  • Review authentication and SSO/SAML-related plugin logs for anomalous or malformed SAML responses, unexpected assertion values, or login events that bypass normal identity provider flows.
  • Audit recent WordPress administrator account creations, role changes, and logins for accounts that don't correspond to known personnel or expected IdP activity.
  • Check for unfamiliar plugins, themes, or file modifications that could indicate post-exploitation persistence following an admin-level compromise.
  • Where feasible, restrict or closely monitor SSO endpoint access and consider disabling the plugin's SAML SSO login path until a fix is confirmed applied.

This is a developing story and details — including affected version ranges and a fix timeline — were not fully specified in initial reporting. Treat the above as high-level hunting guidance rather than a confirmed technical breakdown, and consult the original source for updates: BleepingComputer's coverage.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.