<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/hackers-target-wordpress-sites-in-miniorange-auth-bypass-attacks-ayedwsayu" -->

---
title: Hackers target WordPress sites in miniOrange auth bypass...
description: Attackers are actively exploiting two chained vulnerabilities, CVE-2026-61979 and CVE-2026-15981, in the miniOrange SAML 2.0 Single Sign On plugin for...
canonical: https://daily.dev/posts/hackers-target-wordpress-sites-in-miniorange-auth-bypass-attacks-ayedwsayu
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Hackers target WordPress sites in miniOrange auth bypass attacks | daily.dev
og:description: Attackers are actively exploiting two chained vulnerabilities, CVE-2026-61979 and CVE-2026-15981, in the miniOrange SAML 2.0 Single Sign On plugin for...
og:url: https://daily.dev/posts/hackers-target-wordpress-sites-in-miniorange-auth-bypass-attacks-ayedwsayu
og:image: https://api.daily.dev/og/posts/ayeDWsaYu.png
og:image:alt: Hackers target WordPress sites in miniOrange auth bypass attacks
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Hackers target WordPress sites in miniOrange auth bypass attacks

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 1 upvotes · 0 comments

## Summary

Attackers are actively exploiting two chained vulnerabilities, CVE-2026-61979 and CVE-2026-15981, in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that allow forging SAML responses and logging in as an administrator. The plugin accepts an attacker-chosen signature algorithm and mishandles OpenSSL verification errors, letting a known IdP public key be abused as a shared secret to forge valid signatures. Both bugs were disclosed and patched in July across all seven plugin editions, but the vendor's public advisory only covered the free edition, leaving 30,000 paid customers unaware despite fixes being available. DigitalOcean blocked a suspicious admin session tied to this exploit chain on August 16, and Patchstack has observed scanning and exploitation attempts from six IP addresses across multiple continents. Because paid editions don't show update warnings in the WordPress dashboard, site owners must manually check and upgrade to patched versions.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-in-miniorange-auth-bypass-attacks>

## Questions this post answers

### What are CVE-2026-61979 and CVE-2026-15981 in the miniOrange SAML SSO plugin for WordPress?

They are two chainable authentication bypass vulnerabilities in the miniOrange SAML 2.0 SSO plugin. CVE-2026-61979 lets an attacker force the plugin to accept HMAC-SHA1 signing so it treats the identity provider's public RSA key as a shared secret, enabling forged signatures; CVE-2026-15981 causes an OpenSSL verification error (-1) to be treated as a successful signature check, letting malformed signatures pass and granting admin access.

_Teams running SSO plugins can track fast-moving CVE disclosures like this one on daily.dev._

### Which versions of the miniOrange WordPress SAML SSO plugin fix the auth bypass vulnerabilities?

Fixed versions are: Free single site 5.4.5, Premium single site 13.0.4, Standard single site 17.06, Premium/Enterprise/All-Inclusive multisite 20.2.8, Enterprise/All-Inclusive single site 26.0.3, VIP single site 32.0.8, and VIP multisite 35.0.7. The WordPress dashboard does not show update warnings for the paid editions, so site owners must upgrade manually.

_Anyone patching plugin versions across editions can follow security advisories like this via daily.dev._

### Why didn't WordPress site owners running paid miniOrange plugin editions know they needed to patch the SAML SSO auth bypass bug?

The vendor's public disclosure in July only covered the free edition of the miniOrange SAML SSO plugin, even though patches were released for all six paid editions too. Because the advisory omitted those editions, many paid-version site owners never saw a warning and took no action, leaving them exposed when attackers began actively chaining the two flaws in mid-August.

_Watching for gaps between vendor advisories and actual patched versions matters when managing plugin security via daily.dev._

## Similar posts on daily.dev

- [Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin](https://daily.dev/posts/hackers-exploit-info-disclosure-bug-in-gravity-smtp-wordpress-plugin-4vu35e6v7) · BleepingComputer · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#wordpress](https://daily.dev/tags/wordpress)

[View this post on daily.dev](https://daily.dev/posts/hackers-target-wordpress-sites-in-miniorange-auth-bypass-attacks-ayedwsayu)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Hackers target WordPress sites in miniOrange auth bypass attacks","url":"https://daily.dev/posts/hackers-target-wordpress-sites-in-miniorange-auth-bypass-attacks-ayedwsayu","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/hackers-target-wordpress-sites-in-miniorange-auth-bypass-attacks-ayedwsayu"},"datePublished":"2026-08-24T19:28:27.266Z","dateModified":"2026-09-13T21:11:15.105Z","description":"Attackers are actively exploiting two chained vulnerabilities, CVE-2026-61979 and CVE-2026-15981, in the miniOrange SAML 2.0 Single Sign On plugin for...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/8c3d928f3e9804a1e470ee482a0b1103?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/8c3d928f3e9804a1e470ee482a0b1103?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/hackers-target-wordpress-sites-in-miniorange-auth-bypass-attacks-ayedwsayu","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,wordpress","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"Hackers target WordPress sites in miniOrange auth bypass attacks"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/hackers-target-wordpress-sites-in-miniorange-auth-bypass-attacks-ayedwsayu#faq","mainEntity":[{"@type":"Question","name":"What are CVE-2026-61979 and CVE-2026-15981 in the miniOrange SAML SSO plugin for WordPress?","acceptedAnswer":{"@type":"Answer","text":"They are two chainable authentication bypass vulnerabilities in the miniOrange SAML 2.0 SSO plugin. CVE-2026-61979 lets an attacker force the plugin to accept HMAC-SHA1 signing so it treats the identity provider's public RSA key as a shared secret, enabling forged signatures; CVE-2026-15981 causes an OpenSSL verification error (-1) to be treated as a successful signature check, letting malformed signatures pass and granting admin access. Teams running SSO plugins can track fast-moving CVE disclosures like this one on daily.dev."}},{"@type":"Question","name":"Which versions of the miniOrange WordPress SAML SSO plugin fix the auth bypass vulnerabilities?","acceptedAnswer":{"@type":"Answer","text":"Fixed versions are: Free single site 5.4.5, Premium single site 13.0.4, Standard single site 17.06, Premium/Enterprise/All-Inclusive multisite 20.2.8, Enterprise/All-Inclusive single site 26.0.3, VIP single site 32.0.8, and VIP multisite 35.0.7. The WordPress dashboard does not show update warnings for the paid editions, so site owners must upgrade manually. Anyone patching plugin versions across editions can follow security advisories like this via daily.dev."}},{"@type":"Question","name":"Why didn't WordPress site owners running paid miniOrange plugin editions know they needed to patch the SAML SSO auth bypass bug?","acceptedAnswer":{"@type":"Answer","text":"The vendor's public disclosure in July only covered the free edition of the miniOrange SAML SSO plugin, even though patches were released for all six paid editions too. Because the advisory omitted those editions, many paid-version site owners never saw a warning and took no action, leaving them exposed when attackers began actively chaining the two flaws in mid-August. Watching for gaps between vendor advisories and actual patched versions matters when managing plugin security via daily.dev."}}]}
```

