26 August 2026
Reference: CVE-2026-61979
1. What is being reported?
The MiniOrange plugin for WordPress, which helps users log in securely using Single Sign-On (SSO), has a vulnerability that lets unauthorised people escalate their access rights without logging in properly. This means attackers can potentially take control of the website’s admin area.
2. What this means in plain English
If your website uses this plugin and is not updated, attackers could break in without needing a password and make changes, steal information, or disrupt your site. This can harm your business reputation and lead to data loss or downtime.
3. Could this affect a small business?
Small businesses or organisations using WordPress websites with the MiniOrange SSO plugin version 5.4.3 or earlier are at risk. If you don’t use this plugin or use a newer version, you are likely not affected.
4. What to do now
- Check if your WordPress website uses the MiniOrange Single Sign-On plugin.
- Verify the plugin version and update it immediately to the latest available version.
- If you cannot update right away, consider disabling the plugin temporarily to reduce risk.
- Ask your IT provider to review your website’s security settings and monitor for unusual activity.
5. Ask your IT provider
Can you confirm if our WordPress site uses the MiniOrange Single Sign-On plugin, and if so, has it been updated to fix the recent unauthorised access vulnerability?
6. Bottom line
Keep your WordPress plugins updated to protect your website from attackers gaining admin access through known security flaws.
Information based on CISA KEV, NVD, and reputable security news reports.