A serious security issue affects WordPress websites that use the miniOrange SAML 2.0 Single Sign On plugin.
This issue may allow an attacker to bypass normal login controls and gain administrator access to a website. Exploitation attempts have been reported.
Technical teams or external website providers should urgently confirm, for every WordPress website they manage, whether:
- The miniOrange SAML 2.0 Single Sign On plugin is not installed; or
- The plugin edition and version have been identified, the plugin has been updated to the required fixed version, and the site has been checked for signs of suspicious administrator activity.
This must be confirmed directly by the responsible technical team.
The plugin has several paid editions that use separate version sequences. Standard vulnerability scans and WordPress update notifications may not reliably identify vulnerable paid editions.

