Tuesday, August 25, 2026

Independent technology reporting and practical analysis

Manila ·
CYBERSECURITY

Independent reporting, useful context, and practical analysis.

Back to Technomalist
Cybersecurity / news

Hackers Target miniOrange WordPress SSO Flaws in Active Attacks

Two critical miniOrange SAML SSO vulnerabilities can reportedly be chained to forge login responses and obtain WordPress administrator access.

WordPress website login displayed on a laptop
WordPress website login displayed on a laptop

Attackers are scanning for and exploiting two critical vulnerabilities in miniOrange SAML 2.0 Single Sign On products for WordPress, according to security researchers. When chained, the flaws can allow an attacker to forge a SAML response and gain access to a vulnerable website as an administrator.

The issues are tracked as CVE-2026-61979 and CVE-2026-15981. miniOrange's software lets WordPress sites accept identities from services such as Microsoft Entra ID, Okta, Google Workspace and OneLogin. That makes the plugin especially important in organizations that use centralized login rather than separate WordPress passwords.

How the bypass works

The first flaw concerns the signature algorithm accepted from an incoming SAML response. Researchers found that an attacker could select an algorithm that causes a public key to be treated like a shared secret. Because that public key is available, a forged response could then be signed in a form the plugin accepts.

The second vulnerability involves how an OpenSSL verification error is interpreted. A malformed signature that should be rejected can instead be treated as a successful result. Chaining the two weaknesses can produce an administrator session without legitimate identity-provider credentials.

Patchstack reported that attempts to exploit the vulnerabilities are underway and that a public proof of concept exists. The firm linked an anomalous administrator session blocked by DigitalOcean to exploitation of an older Standard-edition plugin. Public exploit code can make opportunistic scanning spread quickly because attackers no longer need to develop the technique independently.

Paid editions require special attention

Fixes were released for the affected editions, but administrators should not rely exclusively on the normal WordPress update warning. Researchers warned that some paid editions may not display a dashboard alert even though patched versions are available.

The reported fixed releases include Free 5.4.5, Premium 13.0.4, Standard 17.06, multisite Premium or Enterprise 20.2.8, single-site Enterprise 26.0.3, VIP single-site 32.0.8 and VIP multisite 35.0.7. Administrators should verify the exact product edition and version through their miniOrange account or vendor documentation.

Sites that ran an affected version should review administrator accounts, active sessions and authentication logs rather than assuming an update alone resolves a past intrusion. Unexpected users, configuration changes, new plugins and unfamiliar sessions should be investigated. Resetting relevant credentials and invalidating sessions may also be appropriate where exploitation is suspected.

See an error? Read our corrections policy or email [email protected].

MORE FROM TECHNOMALIST

Continue reading

View all
Telecommunications network equipment representing online safety controls
Internet

PLDT Moves to Block Over 100 Sites in Child Online-Safety Push

Remote business meeting shown across multiple computer screens
Software

Microsoft Teams Adds Automatic Blocking for External Meeting Bots

Identity security dashboard representing a blocked cyberattack
Cybersecurity

ReliaQuest Says Device Trust Stopped ShinyHunters Data Theft