Hackers are targeting WordPress sites by exploiting two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin. These vulnerabilities, tracked as CVE-2026-61979 and CVE-2026-15981, can be chained together to bypass authentication mechanisms.
CVE-2026-61979 allows an attacker to force the plugin to accept HMAC-SHA1 as the signature algorithm, treating the identity provider's RSA public key as a shared secret. This enables the attacker to forge a signature that the plugin validates. CVE-2026-15981 causes the plugin to interpret an OpenSSL verification error as a successful result, allowing malformed signatures to pass validation.
Although miniOrange released fixes for these vulnerabilities in July, the vendor's public advisory only mentioned the free edition of the plugin. This oversight left users of the six paid editions unaware of the necessary updates, creating an opportunity for threat actors to exploit unpatched installations. Patchstack reported that DigitalOcean blocked an anomalous WordPress administrator session resulting from these exploits.
The vulnerabilities affect various versions across miniOrange's plugin family, including Free (5.4.5), Premium (13.0.4), Standard (17.06), Premium/Enterprise/All-Inclusive multisite (20.2.8), Enterprise/All-Inclusive single site (26.0.3), VIP single site (32.0.8), and VIP multisite (35.0.7). The exploitation allows attackers to obtain administrator session cookies, as observed in an attack on a site running the Standard edition plugin version 16.1.9.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Hackers are actively exploiting two critical authentication bypass vulnerabilities, CVE-2026-61979 and CVE-2026-15981, in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. These flaws allow attackers to forge SAML responses and gain administrative access, impacting sites that did not update due to incomplete vendor advisories.