Hackers are actively attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress.
The flaws can be chained together to forge SAML responses and gain access to WordPress administrator accounts.
The miniOrange SAML SSO plugin, developed by Xecurify, allows WordPress websites to use SAML-based single sign-on with corporate identity platforms such as Microsoft Entra ID, Okta, Google Workspace and OneLogin. The miniOrange product family includes seven different editions covering both free and paid versions.
The two vulnerabilities are tracked as CVE-2026-61979 and CVE-2026-15981. The first flaw allows attackers to manipulate the signature algorithm used to validate incoming SAML responses. Instead of enforcing the algorithm configured by the website administrator, the plugin accepts the algorithm specified in the incoming response.
Attackers can exploit this behavior by selecting HMAC-SHA1, which causes the plugin to use the identity provider’s RSA public key as the shared secret. Since the public key is already known, an attacker can use it to create a forged signature that the plugin accepts as legitimate.
The second vulnerability, CVE-2026-15981, involves incorrect handling of OpenSSL verification results. The plugin can interpret an OpenSSL verification error represented by -1 as a successful verification, allowing malformed signatures to pass the authentication process.
According to security firm Patchstack, both vulnerabilities were publicly disclosed and fixed in July. However, the vendor’s advisory covered only the free edition, leaving users of the six paid editions without a security alert even though fixes had also been released for those versions.
The patched versions include Free Single Site 5.4.5, Premium Single Site 13.0.4, Standard Single Site 17.06, Premium/Enterprise/All-Inclusive Multisite 20.2.8, Enterprise/All-Inclusive Single Site 26.0.3, VIP Single Site 32.0.8 and VIP Multisite 35.0.7.
The lack of disclosure across the paid editions reportedly caused some website owners to remain unaware of the vulnerabilities. This left vulnerable installations exposed while attackers began looking for systems that had not yet been updated.
Patchstack reported that DigitalOcean blocked an unusual WordPress administrator session on August 16 originating outside its trusted network. An investigation found that attackers had chained the two vulnerabilities against the Standard edition of the plugin, version 16.1.9, to obtain an administrator session cookie.
Patchstack has also observed exploitation attempts and opportunistic scanning originating from six IP addresses across Europe, Africa and the United States. A publicly available proof-of-concept exploit targeting the free edition could further increase attack activity.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
Website owners should also note that paid versions of the miniOrange SAML SSO plugin may not display update warnings inside the WordPress administrator dashboard. Administrators using the plugin should therefore manually check their installed version and upgrade to the appropriate patched release.
Hackers Exploit Critical miniOrange SAML SSO Flaws to Hijack WordPress Admin Accounts





