Critical miniOrange SAML SSO Vulnerabilities Allow WordPress Admin Takeover

Critical miniOrange SAML SSO Vulnerabilities Allow WordPress Admin Takeover

First seen 25 Aug 2026, 07:20 UTC Bleepingcomputerpatchstack.comGbhackersTechtimesSecurityaffairs.Co+4 72.0

Article Content

Browse articles
ThreatCluster

Two critical authentication bypass vulnerabilities (CVE-2026-61979 and CVE-2026-15981) have been identified in the miniOrange SAML 2.0 Single Sign-On plugin for WordPress, allowing unauthenticated attackers to forge SAML assertions and log in as any existing user, including administrators. These vulnerabilities, with a CVSS score of 9.8, were disclosed in July 2026 and have been exploited in the wild, with reports of attacks targeting both free and paid versions of the plugin. The vendor's advisory only covered the free edition, leaving many users of the paid editions unaware of their exposure. DigitalOcean reported blocking anomalous admin sessions linked to these vulnerabilities on August 16, 2026. A proof-of-concept exploit for the free edition was made public shortly after the vulnerabilities were disclosed, increasing the risk of exploitation. Website owners must manually upgrade to patched versions as no update warnings are shown for paid editions.

Key Points: • Two critical vulnerabilities in miniOrange SAML 2.0 plugin allow admin account takeover. • CVE-2026-61979 and CVE-2026-15981 have a CVSS score of 9.8 and were disclosed in July 2026. • Exploitation attempts have been confirmed, with a proof-of-concept exploit available publicly.

Timeline

2026-07-23
CVE-2026-15981 published
The first vulnerability was publicly disclosed, allowing attackers to exploit the miniOrange plugin.
Bleepingcomputer
2026-07-26
Public PoC exploit released
A proof-of-concept exploit targeting the vulnerabilities was made publicly available, increasing risk.
Bleepingcomputer
2026-08-13
CVE-2026-61979 published
The second vulnerability was disclosed, enabling further exploitation of the plugin.
Bleepingcomputer
2026-08-16
DigitalOcean blocks anomalous admin session
DigitalOcean reported blocking an admin session linked to the exploitation of the vulnerabilities.
Bleepingcomputer