TTO-2026-0825-002 · August 25, 2026 Active Exploitation

WordPress miniOrange SAML Plugin Auth Bypass CVE-2026-61979 and CVE-2026-15981 Under Active Exploitation — Enterprise Editions Left Without Advisory

wordpress.orgCVE-2026-61979CVE-2026-15981miniOrange SAML SSOAdmin account takeoverForged SAML responsesEnterprise editions unnotifiedPatchstack30,000 customersDigitalOcean blocked anomalous sessions

Summary

Hackers are actively exploiting two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be chained to forge SAML responses and obtain administrator access to affected sites. CVE-2026-61979 exploits the plugin's acceptance of the signature algorithm from incoming SAML responses rather than enforcing the configured one — an attacker can select HMAC-SHA1, use the known public key as a shared secret, and forge a signature the plugin accepts as authentic. CVE-2026-15981 causes the plugin to interpret an OpenSSL verification error code of negative one as a successful verification result, allowing malformed signatures to pass validation. Chained, the two vulnerabilities allow an unauthenticated attacker to forge a complete SAML response asserting administrator identity and log in to any vulnerable site without credentials. The vulnerabilities were publicly disclosed and fixed in July 2026. However, the vendor's security advisory covered only the free edition of the plugin, leaving customers running any of the six paid enterprise editions without notification that patches existed or were needed. This disclosure gap created an attack opportunity against a substantial portion of miniOrange's 30,000-customer base. Patchstack observed active exploitation beginning on August 16, 2026, when DigitalOcean blocked an anomalous WordPress administrator session originating outside its trusted network on a miniOrange-protected site. Exploitation attempts have continued since.

Timeline

DateEvent
Jul 2026CVE-2026-61979 and CVE-2026-15981 publicly disclosed — fixes released for all editions, free and paid
Jul 2026miniOrange publishes advisory covering free plugin edition only — six paid enterprise editions not mentioned in advisory
Aug 16, 2026Active exploitation begins — DigitalOcean blocks anomalous admin session on miniOrange-protected site
Aug 25, 2026Exploitation attempts ongoing against sites running unpatched enterprise editions

Domain Intelligence

DomainScoreDKIMSPFDMARCStatus
wordpress.org62.01Live
WarmBadge Intelligence Snapshot · Captured: August 25, 2026 UTC

Context

wordpress.org scores 62.01 — the domain of the world's most widely deployed content management system, powering more than 40 percent of all websites on the internet. WordPress itself is not the vulnerability here. The miniOrange SAML SSO plugin is. The disclosure gap — releasing a fix across all editions while publishing a security advisory that mentioned only one — is the operational detail that enabled the exploitation window. Administrators running paid enterprise editions had no basis to know their edition carried the same vulnerability. For sites that had implemented miniOrange SAML SSO specifically to comply with enterprise identity management requirements, an unauthenticated authentication bypass is a complete failure of the security control the plugin was installed to provide.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · August 25, 2026