DATANEWS

Hackers Target WordPress Sites Through Critical miniOrange SAML Authentication Flaws

Patchstack · 2026-08-25

Attackers are attempting to exploit two miniOrange SAML SSO authentication-bypass vulnerabilities that can allow unauthenticated access to WordPress administrator accounts.

Why it matters: The combination of administrator takeover risk and fragmented versioning makes this both an urgent WordPress security issue and a vulnerability-management problem.

Attackers are attempting to exploit critical authentication vulnerabilities in the miniOrange SAML Single Sign-On plugin family that can allow an unauthenticated attacker to forge SAML responses and gain administrator access to WordPress sites.

The vulnerabilities include CVE-2026-61979 and CVE-2026-15981. Patchstack's root-cause analysis, based on work by DigitalOcean's security team, says the flaws affect SAML signature-validation logic and can enable authentication bypasses in vulnerable editions.

The security problem is complicated by miniOrange's product structure. Patchstack says seven separately versioned editions are distributed under a single WordPress plugin identity. Several paid editions received fixes without public advisories or changelog entries, which left public vulnerability databases unable to identify some affected installations accurately.

Patchstack says exploitation has been attempted in the wild, and BleepingComputer separately reported active attacks targeting the vulnerable SAML paths.

The incident highlights a broader software-supply-chain issue: patch availability is not enough if asset inventories and vulnerability scanners cannot determine which product edition and version is actually installed.

Organizations using miniOrange SAML should verify their exact edition and version against the vendor and Patchstack's affected-version matrix rather than relying only on the WordPress dashboard.

Source and attribution →