Junglewise Threat Intelligence

CVE-2026-75807: miniOrange SAML Single Sign On authentication bypass

CVE-2026-75807 · Severity: high · CVSS 7.5 · Published 2026-08-29

Technologies: miniOrange SAML Single Sign On – SSO Login. Vendors: miniOrange.

Executive brief

The SAML Single Sign On – SSO Login plugin for WordPress allows unauthenticated attackers to bypass authentication and hijack any account, including administrator accounts. An attacker can forge login credentials by overwriting the plugin's stored IdP signing certificate with a malicious one, then forge SAML assertions to gain full administrative access to the WordPress site. This requires an administrator to perform a repair action after a test configuration error, but once exploited, it compromises all account security.

Technical details

The vulnerability is an authentication bypass in the mo_saml_login_validate() ACS handler. The root cause is that the plugin persists an X.509 certificate from incoming SAMLResponse into the mo_saml_required_certificate option before signature validation is enforced. The mo_saml_find_certificate() function returns false on fingerprint mismatch instead of halting execution, allowing certificate replacement. An unauthenticated attacker can send a malicious SAML response with an attacker-controlled certificate, which overwrites the legitimate IdP certificate. Subsequently, the attacker can forge SAML assertions signed with their certificate to impersonate any WordPress account. Exploitation requires the administrator to encounter and repair the test_config_error_wpsamlerr004 error during test configuration. No patch information is currently available for versions up to 5.4.6.

Affected products

  • miniOrange SAML Single Sign On – SSO Login up to and including 5.4.6

Timeline

  • 2026-08-29: disclosed

References

Related threats