← All stories
● Covered by 1 source · 1 reportMedium impact1 negative

Hackers Exploit miniOrange SAML SSO WordPress Plugin Vulnerabilities

🔄 Updated 48m ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Two critical authentication bypass vulnerabilities are being exploited.
  • Flaws allow forging SAML responses and gaining admin access.
  • Vendor's advisory only covered the free plugin edition.
  • Exploitation attempts observed on WordPress sites.

Active Exploitation of WordPress Plugin Flaws

Hackers are targeting WordPress sites by exploiting two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin. These vulnerabilities, tracked as CVE-2026-61979 and CVE-2026-15981, can be chained together to bypass authentication mechanisms.

Technical Details of the Vulnerabilities

CVE-2026-61979 allows an attacker to force the plugin to accept HMAC-SHA1 as the signature algorithm, treating the identity provider's RSA public key as a shared secret. This enables the attacker to forge a signature that the plugin validates. CVE-2026-15981 causes the plugin to interpret an OpenSSL verification error as a successful result, allowing malformed signatures to pass validation.

Incomplete Vendor Disclosure Led to Risk

Although miniOrange released fixes for these vulnerabilities in July, the vendor's public advisory only mentioned the free edition of the plugin. This oversight left users of the six paid editions unaware of the necessary updates, creating an opportunity for threat actors to exploit unpatched installations. Patchstack reported that DigitalOcean blocked an anomalous WordPress administrator session resulting from these exploits.

Affected Versions and Impact

The vulnerabilities affect various versions across miniOrange's plugin family, including Free (5.4.5), Premium (13.0.4), Standard (17.06), Premium/Enterprise/All-Inclusive multisite (20.2.8), Enterprise/All-Inclusive single site (26.0.3), VIP single site (32.0.8), and VIP multisite (35.0.7). The exploitation allows attackers to obtain administrator session cookies, as observed in an attack on a site running the Standard edition plugin version 16.1.9.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~7 min · 6 stories · Aug 24

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Hackers are actively exploiting two critical authentication bypass vulnerabilities, CVE-2026-61979 and CVE-2026-15981, in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. These flaws allow attackers to forge SAML responses and gain administrative access, impacting sites that did not update due to incomplete vendor advisories.