Hackers Target miniOrange WordPress Plugin Flaws to Take Over Websites

Hackers exploit critical miniOrange SAML plugin flaws to bypass security and steal admin access on thousands of WordPress websites.

Hackers target miniOrange SAML plugin flaws to bypass logins and take full control of WordPress websites as admin.

Cybersecurity researchers have issued an urgent warning after malicious hackers began actively attacking severe security flaws inside a popular WordPress software tool called the miniOrange SAML Single Sign On plugin.


The affected software is widely used by business websites to allow employees and staff members to log in using corporate accounts like Google, Microsoft, or Okta.

By exploiting these programming bugs, online thieves can trick the website system, bypass regular login passwords, and instantly gain full administrative control over vulnerable online portals.

Once inside, bad actors can edit website files, steal private customer records, or lock owners out entirely.

The dangerous cybersecurity warning was officially published on August 25, 2026, after research experts at the WordPress security platform Patchstack tracked ongoing hacking attempts.

The cyber attacks began spreading across global server networks after cloud provider DigitalOcean noticed suspicious administrative activity originating from an untrusted web address.

While software fixes were originally developed and released in July, many website managers running paid versions of the plugin remain completely unaware of the danger because automatic update alerts were not clearly sent out to website dashboards.

The main reason these online attacks are succeeding is that two distinct programming mistakes inside the plugin can be combined by hackers to create a powerful shortcut.

See Also: WhatsApp Adds Multiple Passkeys and Stronger Passwords to Stop Account Theft

When someone tries to log in, the software is supposed to check a special digital signature to verify the user’s identity.

However, the bug causes the system to confuse its own security keys and misinterpret system error messages as valid approvals.

Because the system evaluates an error code as a successful check, hackers can send a specially broken digital message that tricks the website into instantly opening up its master administrator controls.

Explaining how bad actors are scanning the internet to find unpatched WordPress websites, Patchstack security analysts noted that “the spread suggests opportunistic scanning rather than a targeted campaign,” adding that “whoever is running this appears to be throwing the exploit at every site with the plugin installed without checking which edition or version is behind it”.

Detailing why silent software updates left many business websites exposed to sudden account takeovers, Patchstack security researchers warned that “this is exactly the behavior that makes the silent patch situation dangerous,” emphasizing that “the attacker does not need to know which edition you run, you do”.

Warning website owners that they must check their software manually to stay safe from account hijacking, cybersecurity researchers at Patchstack confirmed that “unauthenticated attackers can log in as any existing WordPress user, including administrators, by submitting a crafted SAMLResponse containing an attacker controlled NameID and a deliberately malformed signature value that triggers an OpenSSL processing error, bypassing verification entirely”.

By taking advantage of unpatched software, cybercriminals are proving how critical it is for website owners to keep their digital tools updated.


Taking a few minutes to manually install the latest plugin version ensures that business websites remain safe, secure, and protected from unauthorized online takeovers.

About the Author

Jennifer Sakmufuwo Baba

Jennifer Sakmufuwo Baba is a tech analyst, senior staff, and writer covering artificial intelligence, cybersecurity , and emerging technologies at TechRegard. Based in Nigeria, she's passionate about translating complex tech developments into compelling, accessible stories for diverse audiences. Her work focuses on how technology shapes innovation across Africa and globally.