Two critical vulnerabilities in the miniOrange SAML 2.0 Single Sign-On plugin for WordPress are being exploited in attacks, allowing unauthenticated attackers to bypass login and gain administrator access. BleepingComputer reports that scans and exploitation attempts have been recorded.

The vulnerabilities are CVE-2026-61979 and CVE-2026-15981, both with a CVSS score of 9.8. Patchstack and DigitalOcean's security team linked the issues to SAML response forgery and administrator session cookie acquisition.
miniOrange SAML is used to connect a WordPress site to identity services like Microsoft Entra ID, Okta, and Google Workspace. So, a problem with the verification process can go from an inability to log in to a complete control panel takeover.
See also: WebToffee WooCommerce: New vulnerability allows reading files

How miniOrange SAML works
CVE-2026-61979 concerns a signature algorithm confusion. The plugin allows the incoming SAML response to declare the algorithm to be used, rather than forcing the one configured by the administrator. The attacker can choose HMAC-SHA1 and use the identity provider's RSA public key as the shared secret.
This key is available from the identity provider metadata, so it can be used to create a fake SAML assertion. If the assertion contains the name of an existing user, miniOrange SAML can consider it valid and issue a login cookie for that account.
CVE -2026-15981 exploits a different flaw in OpenSSL verification. The openssl_verify() returns 1 for a valid signature, 0 for a failed one, and -1 when an internal error occurs. The code treats the value -1 as true, causing a malformed signature to pass the check.

Attacks and information gap
DigitalOcean detected an unusual admin session attempt from an address outside its trusted network on August 16. Investigation revealed that the two vulnerabilities were previously exploited in a chain on a Standard installation running version 16.1.9. The company's defenses prevented further actions in the admin panel.
Patchstack recorded attempts from six IP addresses in Europe, Africa, and the United States. The activity appears to be opportunistic scans that target the endpoint without first checking which version is installed. There is also a public PoC for the free version, which could speed up attacks.
Of particular concern is the fact that the same WordPress slug ID hosts seven different versions of the product. Public databases initially only covered the free version, while the paid versions were patched without a corresponding public entry or notice on the WordPress dashboard.
See also: CVE-2026-18855: Critical vulnerability in WordPress Link Library
Which versions should be installed?
Administrators should identify the version and licensing plan and install the patched version. The free version requires at least 5.4.5, while Premium for a single site requires 13.0.4. In Standard, the safe line is 17.0.6; version 16.x is not expected to receive a patch.
For the remaining versions, the fixes mentioned in the survey are 20.2.8 for Premium, Enterprise and All-Inclusive multisite, 26.0.3 for Enterprise and All-Inclusive single-site, 32.0.8 for VIP single-site and 35.0.7 for VIP multisite. The WordPress plugin directory currently shows the free version 5.4.7.
Upgrading paid versions of miniOrange SAML may require a manual download from the miniOrange portal, as it does not necessarily appear as an update within WordPress. If the installation cannot be upgraded immediately, administrators should temporarily restrict SAML login, check logs, and look for new admin sessions from unexpected addresses.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Elementor Pro: Critical vulnerability allows RCE without authentication
The SecNews technical team recommends an immediate check of all installations using miniOrange SAML, so that owners can confirm that miniOrange SAML has been patched, including paid packages. The absence of a warning in the panel is not an indication of security; the correct version must be confirmed by the installation itself and combined with a check for suspicious connections.
