← All stories
● Covered by 3 sources · 3 reportsMedium impact3 negative

Hackers Exploit miniOrange SAML SSO WordPress Plugin Vulnerabilities

🔄 Updated 37d ago — new reporting from SecurityWeek
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Two critical authentication bypass vulnerabilities are being exploited.
  • Flaws allow forging SAML responses and gaining admin access.
  • Vendor's advisory only covered the free plugin edition.
  • Exploitation attempts observed on WordPress sites.
  • Vulnerabilities are CVE-2026-61979 and CVE-2026-15981.
  • CVE-2026-61979 fixed in version 17.0.5 for Standard edition.
  • CVE-2026-15981 fixed in version 17.0.6 for Standard edition.
  • CVE-2026-15981 has a CVSS score of 9.8.
  • Vulnerabilities affect MiniOrange SAML 2.0 Single Sign-On (SSO) plugin.
  • Over 10,000 WordPress sites use the free edition of the plugin.
  • Vulnerabilities allow attackers to log in as any WordPress user.
  • Patchstack described attacks as opportunistic rather than targeted.
  • Free edition advisory lists fix in version 5.4.5 as a bugfix.

Active Exploitation of WordPress Plugin Flaws

Hackers are targeting WordPress sites by exploiting two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin. These vulnerabilities, tracked as CVE-2026-61979 and CVE-2026-15981, can be chained together to bypass authentication mechanisms.

Technical Details of the Vulnerabilities

CVE-2026-61979 allows an attacker to force the plugin to accept HMAC-SHA1 as the signature algorithm, treating the identity provider's RSA public key as a shared secret. This enables the attacker to forge a signature that the plugin validates. CVE-2026-15981 causes the plugin to interpret an OpenSSL verification error as a successful result, allowing malformed signatures to pass validation.

Incomplete Vendor Disclosure Led to Risk

Although miniOrange released fixes for these vulnerabilities in July, the vendor's public advisory only mentioned the free edition of the plugin. This oversight left users of the six paid editions unaware of the necessary updates, creating an opportunity for threat actors to exploit unpatched installations. Patchstack reported that DigitalOcean blocked an anomalous WordPress administrator session resulting from these exploits.

Affected Versions and Impact

The vulnerabilities affect various versions across miniOrange's plugin family, including Free (5.4.5), Premium (13.0.4), Standard (17.06), Premium/Enterprise/All-Inclusive multisite (20.2.8), Enterprise/All-Inclusive single site (26.0.3), VIP single site (32.0.8), and VIP multisite (35.0.7). The exploitation allows attackers to obtain administrator session cookies, as observed in an attack on a site running the Standard edition plugin version 16.1.9.

Updates

🕒 2026-08-25 · new reporting from SecurityWeek
  • Vulnerabilities affect MiniOrange SAML 2.0 Single Sign-On (SSO) plugin.
  • Over 10,000 WordPress sites use the free edition of the plugin.
  • Vulnerabilities allow attackers to log in as any WordPress user.
  • Patchstack described attacks as opportunistic rather than targeted.
  • Free edition advisory lists fix in version 5.4.5 as a bugfix.
🕒 2026-08-25 · new reporting from The Hacker News
  • Vulnerabilities are CVE-2026-61979 and CVE-2026-15981.
  • CVE-2026-61979 fixed in version 17.0.5 for Standard edition.
  • CVE-2026-15981 fixed in version 17.0.6 for Standard edition.
  • CVE-2026-15981 has a CVSS score of 9.8.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Threat actors are exploiting two critical authentication bypass vulnerabilities, CVE-2026-61979 and CVE-2026-15981, in the MiniOrange SAML 2.0 Single Sign-On (SSO) plugin for WordPress. These vulnerabilities allow attackers to log in as any WordPress user, including administrators, and affect over 10,000 WordPress sites using the free edition of the plugin, with paid versions also impacted.

Attackers are actively exploiting two severe authentication bypass vulnerabilities in the Xecurify miniOrange SAML 2.0 Single Sign On plugin for WordPress, allowing unauthenticated users to gain administrator access. These flaws, CVE-2026-61979 and CVE-2026-15981, enable attackers to log in as any WordPress user by submitting crafted SAML responses with malformed signatures. This impacts WordPress sites using the vulnerable plugin, making them susceptible to unauthorized administrative control.

Hackers are actively exploiting two critical authentication bypass vulnerabilities, CVE-2026-61979 and CVE-2026-15981, in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. These flaws allow attackers to forge SAML responses and gain administrative access, impacting sites that did not update due to incomplete vendor advisories.