Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

Security Flaw in WordPress MiniOrange Plugin Could Let Attackers Take Over Your Website

A serious security weakness has been found in certain versions of the MiniOrange Single Sign-On plugin used by WordPress websites. This flaw could allow attackers to bypass login controls and gain full admin access, putting your website and data at risk.

26 August 2026

Reference: CVE-2026-61979

1. What is being reported?

The MiniOrange plugin for WordPress, which helps users log in securely using Single Sign-On (SSO), has a vulnerability that lets unauthorised people escalate their access rights without logging in properly. This means attackers can potentially take control of the website’s admin area.

2. What this means in plain English

If your website uses this plugin and is not updated, attackers could break in without needing a password and make changes, steal information, or disrupt your site. This can harm your business reputation and lead to data loss or downtime.

3. Could this affect a small business?

Small businesses or organisations using WordPress websites with the MiniOrange SSO plugin version 5.4.3 or earlier are at risk. If you don’t use this plugin or use a newer version, you are likely not affected.

4. What to do now

  • Check if your WordPress website uses the MiniOrange Single Sign-On plugin.
  • Verify the plugin version and update it immediately to the latest available version.
  • If you cannot update right away, consider disabling the plugin temporarily to reduce risk.
  • Ask your IT provider to review your website’s security settings and monitor for unusual activity.

5. Ask your IT provider

Can you confirm if our WordPress site uses the MiniOrange Single Sign-On plugin, and if so, has it been updated to fix the recent unauthorised access vulnerability?

6. Bottom line

Keep your WordPress plugins updated to protect your website from attackers gaining admin access through known security flaws.

Information based on CISA KEV, NVD, and reputable security news reports.

Back to Vulnerability Briefs