CVE Tools

Hackers target WordPress sites in miniOrange auth bypass attacks

BleepingComputerBy Bill Toulas

Reported exploitedminiOrange SAML SSO PluginWordPress

Our summary

Threat actors are actively chaining two critical authentication bypass vulnerabilities, tracked as CVE-2026-61979 and CVE-2026-15981, within the miniOrange SAML 2.0 Single Sign On plugin for WordPress. These flaws allow attackers to forge SAML responses using HMAC-SHA1 and misinterpreted OpenSSL verification errors to log in as site administrators. Although fixed versions were released in July for all editions of the plugin, incomplete vendor disclosure regarding the paid tiers left many installations vulnerable to recent exploitation attempts. Site owners should manually update to patched releases, such as version 17.06 for the Standard edition, as automatic dashboard alerts may not trigger for premium versions.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store