The miniOrange SAML 2.0 Single Sign On plugin is a WordPress plugin that enables SAML-based authentication. It is affected by two critical vulnerabilities (CVE-2026-61979 and CVE-2026-15981) that allow authentication bypass and privilege escalation. Patches are available in versions 17.0.5 and 17.0.6.