
Attackers are scanning for and exploiting two critical vulnerabilities in miniOrange SAML 2.0 Single Sign On products for WordPress, according to security researchers. When chained, the flaws can allow an attacker to forge a SAML response and gain access to a vulnerable website as an administrator.
The issues are tracked as CVE-2026-61979 and CVE-2026-15981. miniOrange's software lets WordPress sites accept identities from services such as Microsoft Entra ID, Okta, Google Workspace and OneLogin. That makes the plugin especially important in organizations that use centralized login rather than separate WordPress passwords.
How the bypass works
The first flaw concerns the signature algorithm accepted from an incoming SAML response. Researchers found that an attacker could select an algorithm that causes a public key to be treated like a shared secret. Because that public key is available, a forged response could then be signed in a form the plugin accepts.
The second vulnerability involves how an OpenSSL verification error is interpreted. A malformed signature that should be rejected can instead be treated as a successful result. Chaining the two weaknesses can produce an administrator session without legitimate identity-provider credentials.
Patchstack reported that attempts to exploit the vulnerabilities are underway and that a public proof of concept exists. The firm linked an anomalous administrator session blocked by DigitalOcean to exploitation of an older Standard-edition plugin. Public exploit code can make opportunistic scanning spread quickly because attackers no longer need to develop the technique independently.
Paid editions require special attention
Fixes were released for the affected editions, but administrators should not rely exclusively on the normal WordPress update warning. Researchers warned that some paid editions may not display a dashboard alert even though patched versions are available.
The reported fixed releases include Free 5.4.5, Premium 13.0.4, Standard 17.06, multisite Premium or Enterprise 20.2.8, single-site Enterprise 26.0.3, VIP single-site 32.0.8 and VIP multisite 35.0.7. Administrators should verify the exact product edition and version through their miniOrange account or vendor documentation.
Sites that ran an affected version should review administrator accounts, active sessions and authentication logs rather than assuming an update alone resolves a past intrusion. Unexpected users, configuration changes, new plugins and unfamiliar sessions should be investigated. Resetting relevant credentials and invalidating sessions may also be appropriate where exploitation is suspected.
See an error? Read our corrections policy or email [email protected].
TECHNOMALIST

