Hackers target WordPress sites in miniOrange auth bypass attacks
Reported exploitedminiOrange SAML SSO PluginWordPressOur summary
Threat actors are actively chaining two critical authentication bypass vulnerabilities, tracked as CVE-2026-61979 and CVE-2026-15981, within the miniOrange SAML 2.0 Single Sign On plugin for WordPress. These flaws allow attackers to forge SAML responses using HMAC-SHA1 and misinterpreted OpenSSL verification errors to log in as site administrators. Although fixed versions were released in July for all editions of the plugin, incomplete vendor disclosure regarding the paid tiers left many installations vulnerable to recent exploitation attempts. Site owners should manually update to patched releases, such as version 17.06 for the Standard edition, as automatic dashboard alerts may not trigger for premium versions.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.