Exploitation of miniOrange Auth Bypass Vulnerabilities in WordPress Sites

Exploitation of miniOrange Auth Bypass Vulnerabilities in WordPress Sites

First seen 25 Aug 2026, 07:20 UTC Bleepingcomputerpatchstack.com 74.0

Article Content

Browse articles
ThreatCluster

Hackers are actively exploiting two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, tracked as CVE-2026-61979 and CVE-2026-15981. These vulnerabilities allow attackers to forge SAML responses and log in as administrators. The miniOrange plugin enables users to authenticate via corporate identity platforms, making it widely used. The vulnerabilities were disclosed and patched in July 2026, but the vendor's advisory only covered the free edition, leaving paid versions vulnerable. DigitalOcean reported blocking anomalous admin sessions on August 16, indicating active exploitation attempts. Attackers are leveraging these flaws to obtain admin session cookies, with exploitation attempts originating from multiple IP addresses across Europe, Africa, and the U.S. A public proof-of-concept exploit for the free edition is available, raising concerns about an increase in attacks. Website owners are urged to manually upgrade to patched releases as the admin dashboard will not show update warnings for paid versions.

Key Points: • Two critical vulnerabilities in miniOrange SAML plugin allow admin access via SAML response forgery. • CVE-2026-61979 and CVE-2026-15981 were disclosed in July 2026 but only the free version was alerted. • Active exploitation confirmed with anomalous admin sessions reported by DigitalOcean on August 16.

Timeline

2026-07-23
CVE-2026-15981 published
The first vulnerability was publicly disclosed, allowing attackers to bypass authentication.
BleepingComputer
2026-08-13
CVE-2026-61979 published
The second vulnerability was disclosed, enabling further exploitation through signature forgery.
BleepingComputer
2026-08-16
DigitalOcean blocks anomalous admin sessions
DigitalOcean reported blocking admin sessions from outside its trusted network, indicating exploitation attempts.
BleepingComputer
Recent
Public PoC exploit available
A proof-of-concept exploit targeting the free edition of the miniOrange plugin is now publicly available.
BleepingComputer