Summary
Hackers are actively exploiting two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be chained to forge SAML responses and obtain administrator access to affected sites. CVE-2026-61979 exploits the plugin's acceptance of the signature algorithm from incoming SAML responses rather than enforcing the configured one — an attacker can select HMAC-SHA1, use the known public key as a shared secret, and forge a signature the plugin accepts as authentic. CVE-2026-15981 causes the plugin to interpret an OpenSSL verification error code of negative one as a successful verification result, allowing malformed signatures to pass validation. Chained, the two vulnerabilities allow an unauthenticated attacker to forge a complete SAML response asserting administrator identity and log in to any vulnerable site without credentials. The vulnerabilities were publicly disclosed and fixed in July 2026. However, the vendor's security advisory covered only the free edition of the plugin, leaving customers running any of the six paid enterprise editions without notification that patches existed or were needed. This disclosure gap created an attack opportunity against a substantial portion of miniOrange's 30,000-customer base. Patchstack observed active exploitation beginning on August 16, 2026, when DigitalOcean blocked an anomalous WordPress administrator session originating outside its trusted network on a miniOrange-protected site. Exploitation attempts have continued since.
Timeline
| Date | Event |
|---|---|
| Jul 2026 | CVE-2026-61979 and CVE-2026-15981 publicly disclosed — fixes released for all editions, free and paid |
| Jul 2026 | miniOrange publishes advisory covering free plugin edition only — six paid enterprise editions not mentioned in advisory |
| Aug 16, 2026 | Active exploitation begins — DigitalOcean blocks anomalous admin session on miniOrange-protected site |
| Aug 25, 2026 | Exploitation attempts ongoing against sites running unpatched enterprise editions |
Domain Intelligence
| Domain | Score | DKIM | SPF | DMARC | Status |
|---|---|---|---|---|---|
| wordpress.org | 62.01 | ✓ | ✓ | ✓ | Live |
Context
wordpress.org scores 62.01 — the domain of the world's most widely deployed content management system, powering more than 40 percent of all websites on the internet. WordPress itself is not the vulnerability here. The miniOrange SAML SSO plugin is. The disclosure gap — releasing a fix across all editions while publishing a security advisory that mentioned only one — is the operational detail that enabled the exploitation window. Administrators running paid enterprise editions had no basis to know their edition carried the same vulnerability. For sites that had implemented miniOrange SAML SSO specifically to comply with enterprise identity management requirements, an unauthenticated authentication bypass is a complete failure of the security control the plugin was installed to provide.
The Trust Observatory · thetrustobservatory.com · August 25, 2026