WordPress miniOrange plugin flaws exploited for admin account takeover
Two critical authentication bypass vulnerabilities in the miniOrange SAML Single Sign On plugin for WordPress are being actively exploited. Attackers can chain the flaws to forge SAML responses and gain administrator access. The vendor fixed the issues but only disclosed the risk for the free version, leaving paid users unaware.
The miniOrange plugin family spans seven products, with the free version alone accounting for 10,000 downloads and roughly 30,000 customers across the paid editions. The flaws let attackers select HMAC-SHA1 as the signature algorithm, causing the plugin to treat the identity provider's public key as a shared secret, while a second bug allowed malformed signatures to pass OpenSSL verification.
Patchstack observed exploitation attempts originating from six IP addresses across Europe, Africa, and the United States. A proof-of-concept for the free edition is publicly available, and because WordPress dashboards do not display update warnings for paid plugin versions, administrators must manually check for patched releases.
Organizations relying on this plugin for single sign-on face a serious exposure window, as many paid-version users were never alerted to the risk. Compromised administrator accounts could allow attackers to modify site content, inject malicious code, or harvest user data. Smaller businesses without dedicated security teams may be especially vulnerable, and the public PoC could accelerate attacks across the WordPress ecosystem.