HomeSecurityminiOrange SAML: Critical login bypass threatens WordPress

miniOrange SAML: Critical login bypass threatens WordPress

Two critical vulnerabilities in the miniOrange SAML 2.0 Single Sign-On plugin for WordPress are being exploited in attacks, allowing unauthenticated attackers to bypass login and gain administrator access. BleepingComputer reports that scans and exploitation attempts have been recorded.

miniOrange SAML critical login bypass in WordPress

The vulnerabilities are CVE-2026-61979 and CVE-2026-15981, both with a CVSS score of 9.8. Patchstack and DigitalOcean's security team linked the issues to SAML response forgery and administrator session cookie acquisition.

miniOrange SAML is used to connect a WordPress site to identity services like Microsoft Entra ID, Okta, and Google Workspace. So, a problem with the verification process can go from an inability to log in to a complete control panel takeover.

See also: WebToffee WooCommerce: New vulnerability allows reading files

miniOrange SAML and the risk of login bypass in WordPress

How miniOrange SAML works

CVE-2026-61979 concerns a signature algorithm confusion. The plugin allows the incoming SAML response to declare the algorithm to be used, rather than forcing the one configured by the administrator. The attacker can choose HMAC-SHA1 and use the identity provider's RSA public key as the shared secret.

This key is available from the identity provider metadata, so it can be used to create a fake SAML assertion. If the assertion contains the name of an existing user, miniOrange SAML can consider it valid and issue a login cookie for that account.

CVE -2026-15981 exploits a different flaw in OpenSSL verification. The openssl_verify() returns 1 for a valid signature, 0 for a failed one, and -1 when an internal error occurs. The code treats the value -1 as true, causing a malformed signature to pass the check.

Fake SAML response passes miniOrange SAML check

Attacks and information gap

DigitalOcean detected an unusual admin session attempt from an address outside its trusted network on August 16. Investigation revealed that the two vulnerabilities were previously exploited in a chain on a Standard installation running version 16.1.9. The company's defenses prevented further actions in the admin panel.

Patchstack recorded attempts from six IP addresses in Europe, Africa, and the United States. The activity appears to be opportunistic scans that target the endpoint without first checking which version is installed. There is also a public PoC for the free version, which could speed up attacks.

Of particular concern is the fact that the same WordPress slug ID hosts seven different versions of the product. Public databases initially only covered the free version, while the paid versions were patched without a corresponding public entry or notice on the WordPress dashboard.

See also: CVE-2026-18855: Critical vulnerability in WordPress Link Library

Which versions should be installed?

Administrators should identify the version and licensing plan and install the patched version. The free version requires at least 5.4.5, while Premium for a single site requires 13.0.4. In Standard, the safe line is 17.0.6; version 16.x is not expected to receive a patch.

For the remaining versions, the fixes mentioned in the survey are 20.2.8 for Premium, Enterprise and All-Inclusive multisite, 26.0.3 for Enterprise and All-Inclusive single-site, 32.0.8 for VIP single-site and 35.0.7 for VIP multisite. The WordPress plugin directory currently shows the free version 5.4.7.

Upgrading paid versions of miniOrange SAML may require a manual download from the miniOrange portal, as it does not necessarily appear as an update within WordPress. If the installation cannot be upgraded immediately, administrators should temporarily restrict SAML login, check logs, and look for new admin sessions from unexpected addresses.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Suspicious WordPress admin session check after miniOrange SAML vulnerability

See also: Elementor Pro: Critical vulnerability allows RCE without authentication

The SecNews technical team recommends an immediate check of all installations using miniOrange SAML, so that owners can confirm that miniOrange SAML has been patched, including paid packages. The absence of a warning in the panel is not an indication of security; the correct version must be confirmed by the installation itself and combined with a check for suspicious connections.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS