miniOrange SAML auth bypasses were exploited before paid editions were even flagged Two CVSS 9.8 flaws, CVE-2026-61979 and CVE-2026-15981, in the miniOrange SAML 2.0 Single Sign On WordPress plugin allow unauthenticated login as any existing user, including admins. Patchstack’s analysis shows the paid editions shared one plugin slug but used separate version lines, leaving them absent from vulnerability databases while exploitation was already confirmed. The key issue was not just the bugs