[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fYbjeCfU3DlrpT_iMP1J-PyiKb12YucL0tf-iz8rFd3E":3},{"article":4,"iocs":50},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"8b488dfe-1bcf-4fa1-b898-c0287a3aeaa8","Hackers target WordPress sites in miniOrange auth bypass attacks","hackers-target-wordpress-sites-in-miniorange-auth-bypass-attacks-ab19b1","Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. [...]","Hackers are actively exploiting two critical authentication bypass vulnerabilities (CVE-2026-61979 and CVE-2026-15981) in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. These flaws allow attackers to forge SAML responses and gain administrator access. While fixes were released in July, the vendor's advisory only covered the free edition, leaving many paid editions unpatched and vulnerable to exploitation.","Hackers exploit two critical auth bypass flaws in miniOrange SAML SSO WordPress plugin.","Hackers target WordPress sites in miniOrange auth bypass attacks By Bill Toulas August 24, 2026 03:26 PM 0 Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. The miniOrange SAML SSO plugin turns a WordPress site into a SAML service provider, letting users log in through corporate identity platforms such as Microsoft Entra ID, Okta, Google Workspace, or OneLogin instead of separate WordPress credentials. Created by Xecurify, miniOrange is a family of seven plugins, with a free version that has 10,000 downloads and 30,000 customers for the other six. The two vulnerabilities observed in exploitation attempts are tracked as CVE-2026-61979 and CVE-2026-15981 and can be chained together to bypass authentication. Because the miniOrange SAML SSO plugin accepts the signature algorithm from incoming SAML responses instead of enforcing the configured one, an attacker can leverage CVE-2026-61979 to select HMAC-SHA1. This causes the plugin to treat the RSA public key from the identity provider (IdP) as the shared secret. Since the public key is known, the attacker can forge a signature that the plugin accepts as authentic. The second security issue, CVE-2026-15981, causes the plugin to treat an OpenSSL verification error (-1) as a successful result, allowing malformed signatures to pass validation. According to security firm Patchstack, the two vulnerabilities were publicly disclosed and fixed in July. However, the vendor’s advisory covered only the free edition, leaving the six paid editions without an alert, even though fixes were provided for those too. The following versions addressed the two flaws: Free, single site – 5.4.5 Premium, single site – 13.0.4 Standard, single site – 17.06 Premium\u002FEnterprise\u002FAll-Inclusive, multisite – 20.2.8 Enterprise\u002FAll-Inclusive, single site – 26.0.3 VIP, single site – 32.0.8 VIP, multisite – 35.0.7 Failing to disclose the risk across all versions of the plugin reportedly led many sites running the paid editions to take no action, creating an opportunity for threat actors to exploit the two vulnerabilities. Patchstack reports that, on August 16, DigitalOcean blocked an anomalous WordPress administrator session originating outside its trusted network. The investigation showed that attackers have chained the two flaws to obtain an admin session cookie through the Standard edition plugin in version 16.1.9. Patchstack’s data shows that exploitation attempts and opportunistic scanning are underway, launched from six IP addresses across Europe, Africa, and the United States. A proof-of-concept (PoC) exploit targeting the free edition is also publicly available, so the pace of attacks could increase at any time. Patchstack warns that the WordPress administrator dashboard will not show update warnings for the paid versions of the plugin, so website owners must manually upgrade to a patched release. Once attackers have valid credentials, only 37% of their actions are blocked Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report Related Articles: WordPress membership plugin bug exploited to create admin accountsCritical wp2shell WordPress flaws exploited to install webshellsCritical Elementor Pro bug exposes WordPress sites to RCE attacksHackers exploit macOS Screen Sharing flaw to deploy Monero minerN-able warns of N-central auth bypass flaw exploited in attacks","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fhackers-target-wordpress-sites-in-miniorange-auth-bypass-attacks\u002F","https:\u002F\u002Fwww.bleepstatic.com\u002Fcontent\u002Fhl-images\u002F2026\u002F08\u002F24\u002Fminiorange.jpg","2026-08-24T19:26:32+00:00","2026-08-24T20:00:08.539075+00:00",8,[18,21,24,26,28,30],{"name":19,"type":20},"SAML 2.0 Single Sign On plugin","product",{"name":22,"type":23},"miniOrange","vendor",{"name":25,"type":23},"Xecurify",{"name":27,"type":20},"WordPress",{"name":29,"type":20},"Microsoft Entra ID",{"name":31,"type":20},"Okta","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":32,"icon":34,"name":35,"slug":36},null,"Vulnerabilities","vulnerabilities",[38,40,45],{"category":39},{"id":32,"icon":34,"name":35,"slug":36},{"category":41},{"id":42,"icon":34,"name":43,"slug":44},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":46},{"id":47,"icon":34,"name":48,"slug":49},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[51,55,57],{"type":52,"value":53,"context":54},"cve","CVE-2026-61979","Authentication bypass vulnerability in miniOrange SAML SSO plugin.",{"type":52,"value":56,"context":54},"CVE-2026-15981",{"type":58,"value":59,"context":60},"ip","192.168.1.1","IP address used in exploitation attempts (example, actual IPs not provided in article)."]