The plugin used the identity provider's public key as a shared secret — and only the free edition got told
2026-08-26Security
Two flaws in miniOrange's SAML SSO plugin for WordPress chain into a full authentication bypass, and attacks are already underway. One lets an attacker sign assertions with a key everybody has. The other treats an OpenSSL verification error as a pass. Fixes exist for all seven editions; the vendor's advisory covered one.