
Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that allow spoofing SAML responses and logging in as an administrator.
The miniOrange SAML SSO plugin turns a WordPress site into a SAML service provider and allows users to log in using corporate identity platforms such as Microsoft Entra ID, Okta, Google Workspace or OneLogin instead of separate WordPress credentials.
Developed by Xecurify, miniOrange is a family of seven plugins, of which there is a free version 10,000 downloads And 30,000 customers for the other six.
The two vulnerabilities observed in exploitation attempts are tracked as CVE-2026-61979 and CVE-2026-15981 and can be chained together to bypass authentication.
Because the miniOrange SAML SSO plugin accepts the signature algorithm of incoming SAML responses instead of enforcing the configured one, an attacker can use CVE-2026-61979 to select HMAC-SHA1. This causes the plugin to treat the Identity Provider (IdP) RSA public key as a shared secret.
Since the public key is known, the attacker can forge a signature that the plugin accepts as authentic.
The second security issue, CVE-2026-15981, causes the plugin to treat an OpenSSL verification error (-1) as a successful result, allowing bad signatures to pass validation.
Accordingly Security company PatchstackThe two vulnerabilities were publicly disclosed and fixed in July. However, the provider’s recommendation only covered the free edition, so no warning was displayed for the six paid editions, although fixes were also provided for them.
The two deficiencies have been corrected in the following versions:
- Free, Single Page – 5.4.5
- Premium, Single Page – 13.0.4
- Standard, single location – June 17th
- Premium/Enterprise/All-Inclusive, Multisite – 20.2.8
- Enterprise/All-Inclusive, Single Location – 03/26
- VIP, Single Location – 08/32
- VIP, Multisite – 35.0.7
The failure to disclose the risk for all versions of the plugin reportedly led to many websites using the paid editions taking no action, providing threat actors with an opportunity to exploit the two vulnerabilities.
Patchstack reports that on August 16, DigitalOcean blocked an unusual WordPress administrator session that originated outside of its trusted network.
The investigation revealed that attackers chained the two vulnerabilities to obtain an admin session cookie via the Standard Edition plugin in version 16.1.9.
Patchstack’s data shows that exploitation attempts and opportunistic scans are underway, launched from six IP addresses in Europe, Africa and the United States.
A proof-of-concept (PoC) exploit targeting the free edition is also publicly available, meaning the pace of attacks could increase at any time.
Patchstack warns that the WordPress admin dashboard does not show update alerts for the paid versions of the plugin, requiring site owners to manually update to a patched version.
Overall prevention scores can hide what happens after the first access. Once attackers use valid credentials, prevention drops sharply.
The 2026 Blue Report measures defense technology for technology in 338 million simulations conducted in customer production environments.


