Hackers are targeting WordPress sites by exploiting two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin. These vulnerabilities, tracked as CVE-2026-61979 and CVE-2026-15981, can be chained together to bypass authentication mechanisms.
CVE-2026-61979 allows an attacker to force the plugin to accept HMAC-SHA1 as the signature algorithm, treating the identity provider's RSA public key as a shared secret. This enables the attacker to forge a signature that the plugin validates. CVE-2026-15981 causes the plugin to interpret an OpenSSL verification error as a successful result, allowing malformed signatures to pass validation.
Although miniOrange released fixes for these vulnerabilities in July, the vendor's public advisory only mentioned the free edition of the plugin. This oversight left users of the six paid editions unaware of the necessary updates, creating an opportunity for threat actors to exploit unpatched installations. Patchstack reported that DigitalOcean blocked an anomalous WordPress administrator session resulting from these exploits.
The vulnerabilities affect various versions across miniOrange's plugin family, including Free (5.4.5), Premium (13.0.4), Standard (17.06), Premium/Enterprise/All-Inclusive multisite (20.2.8), Enterprise/All-Inclusive single site (26.0.3), VIP single site (32.0.8), and VIP multisite (35.0.7). The exploitation allows attackers to obtain administrator session cookies, as observed in an attack on a site running the Standard edition plugin version 16.1.9.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Threat actors are exploiting two critical authentication bypass vulnerabilities, CVE-2026-61979 and CVE-2026-15981, in the MiniOrange SAML 2.0 Single Sign-On (SSO) plugin for WordPress. These vulnerabilities allow attackers to log in as any WordPress user, including administrators, and affect over 10,000 WordPress sites using the free edition of the plugin, with paid versions also impacted.
Attackers are actively exploiting two severe authentication bypass vulnerabilities in the Xecurify miniOrange SAML 2.0 Single Sign On plugin for WordPress, allowing unauthenticated users to gain administrator access. These flaws, CVE-2026-61979 and CVE-2026-15981, enable attackers to log in as any WordPress user by submitting crafted SAML responses with malformed signatures. This impacts WordPress sites using the vulnerable plugin, making them susceptible to unauthorized administrative control.
Hackers are actively exploiting two critical authentication bypass vulnerabilities, CVE-2026-61979 and CVE-2026-15981, in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. These flaws allow attackers to forge SAML responses and gain administrative access, impacting sites that did not update due to incomplete vendor advisories.