Exploited miniOrange SAML flaws stay invisible to every vulnerability scanner
Two authentication flaws in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, exploited since mid-August 2026, let an unauthenticated visitor become an administrator. The six paid editions never received a public advisory, so no vulnerability scanner could detect them.