CVE Tools
Back to feed
Exploited in the wild miniOrange SAML SSO Plugin auth-bypass WordPress Xecurify web-app

Hackers target WordPress sites in miniOrange auth bypass attacks

BleepingComputer·By Bill Toulas··2 min read
CVE Tools coverage

Threat actors are actively chaining two critical authentication bypass vulnerabilities, tracked as CVE-2026-61979 and CVE-2026-15981, within the miniOrange SAML 2.0 Single Sign On plugin for WordPress. These flaws allow attackers to forge SAML responses using HMAC-SHA1 and misinterpreted OpenSSL verification errors to log in as site administrators. Although fixed versions were released in July for all editions of the plugin, incomplete vendor disclosure regarding the paid tiers left many installations vulnerable to recent exploitation attempts. Site owners should manually update to patched releases, such as version 17.06 for the Standard edition, as automatic dashboard alerts may not trigger for premium versions.