Bleepingcomputer
Exploitation of miniOrange Auth Bypass Vulnerabilities in WordPress Sites
Article Content
Hackers are actively exploiting two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, tracked as CVE-2026-61979 and CVE-2026-15981. These vulnerabilities allow attackers to forge SAML responses and log in as administrators. The miniOrange plugin enables users to authenticate via corporate identity platforms, making it widely used. The vulnerabilities were disclosed and patched in July 2026, but the vendor's advisory only covered the free edition, leaving paid versions vulnerable. DigitalOcean reported blocking anomalous admin sessions on August 16, indicating active exploitation attempts. Attackers are leveraging these flaws to obtain admin session cookies, with exploitation attempts originating from multiple IP addresses across Europe, Africa, and the U.S. A public proof-of-concept exploit for the free edition is available, raising concerns about an increase in attacks. Website owners are urged to manually upgrade to patched releases as the admin dashboard will not show update warnings for paid versions.
Key Points: • Two critical vulnerabilities in miniOrange SAML plugin allow admin access via SAML response forgery. • CVE-2026-61979 and CVE-2026-15981 were disclosed in July 2026 but only the free version was alerted. • Active exploitation confirmed with anomalous admin sessions reported by DigitalOcean on August 16.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.