miniOrange Vulnerabilities Actively Exploited on WordPress, Risking Authentication Bypass

Views: 81 views

465/69 Wednesday, August 26, 2026

Security researchers have disclosed attacks targeting WordPress websites by exploiting two Critical vulnerabilities, CVE-2026-61979 and CVE-2026-15981, in the miniOrange SAML 2.0 Single Sign On plugin. The vulnerabilities can be chained to forge SAML responses and bypass authentication, allowing attackers to log in with website administrator privileges. Patchstack has already detected exploitation attempts and scanning activity targeting affected websites.

Both vulnerabilities are related to the signature validation process for SAML responses. CVE-2026-61979 allows attackers to use the Identity Provider’s public key as a shared secret to generate an HMAC-SHA1 signature that the system accepts. CVE-2026-15981 is caused by improper validation of OpenSSL results, allowing invalid signatures to be accepted in some cases. Patchstack observed attacks chaining both vulnerabilities against Standard Edition version 16.1.9 to obtain the session cookie of an administrator account.

The vulnerabilities have been fixed in Free Edition 5.4.5, Premium Edition 13.0.4, Standard Edition 17.06, Premium/Enterprise/All-Inclusive Multisite 20.2.8, Enterprise/All-Inclusive 26.0.3, VIP 32.0.8, and VIP Multisite 35.0.7. WordPress administrators using the plugin should check their edition and update to a fixed version, especially for paid editions that may not show update notifications through the WordPress dashboard and may require manual download from the miniOrange account.

Source: https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-in-miniorange-auth-bypass-attacks/