Search
Find merged stories by title or summary.
Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable
Two CVSS 9. 8 miniOrange SAML WordPress plugin auth bypasses were exploited while paid editions never appeared in any vulnerability database. Manual patch required. Two critical authentication bypass vulnerabilities in the miniOrange SAML 2. 0 Single Sign On WordPress plugin, both rated CVSS 9. 8, are under active exploitation. Both CVE-2026-61979 and CVE-2026-15981 allow an unauthenticated attacker to forge a SAML authentication response and arrive in /wp-admin as any existing user, including administrators. The bugs are independent and both have been confirmed exploited in the wild. CVE-2026-61979 is an algorithm confusion flaw. The plugin trusts the incoming SAML response to declare its own signature algorithm. An attacker sets that algorithm to HMAC-SHA1, which causes the plugin to use the identity provider’s RSA public key as the HMAC secret.
WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities
CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin. The post WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities appeared first on SecurityWeek .
Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators. The vulnerabilities, as disclosed by Patchstack, are listed below - CVE-2026-61979 (CVSS score: 8.1) - An unauthenticated privilege escalation
Critical WordPress SAML SSO Flaws Enable Unauthenticated Admin Account Takeover
Two critical vulnerabilities in the miniOrange SAML 2.0 Single Sign-On WordPress plugin could allow unauthenticated attackers to forge SAML assertions and access /wp-admin as any existing account, including administrators. The flaws, tracked as CVE-2026-61979 and CVE-2026-15981, carry a CVSS score of 9.8 and have reportedly been targeted by opportunistic scanning activity. DigitalOcean’s security team detected and blocked an anomalous WordPress administrator session attempt on its infrastructure, and then reproduced both bypasses in miniOrange’s Standard edition, version 16. 1. 9. Critical WordPress SAML SSO Flaws Patchstack coordinated vendor follow-up and expanded its vulnerability database coverage after discovering that the plugin’s distribution model obscured exposure across paid editions. CVE-2026-61979 stems from signature-algorithm confusion.
You've reached the end of current stories for this search.
