Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions.
https://www.securityweek.com/wordpress-websites-targeted-via-miniorange-plugin-vulnerabilities/
https://securityaffairs.com/197815/security/two-cvss-9-8-auth-bypasses-in-miniorange-saml-wordpress-plugin-were-exploited-before-any-database-even-listed-the-paid-editions-as-vulnerable.html
https://patchstack.com/database/wordpress/plugin/miniorange-saml-20-single-sign-on/vulnerability/wordpress-saml-sp-single-sign-on-plugin-5-4-3-privilege-escalation-vulnerability?_s_id=cve
Source: Mitre, NVD
Published: 2026-08-13
Updated: 2026-08-14
Base Score: 7.6
Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C
Severity: High
Base Score: 8.1
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.00271