Vulnerability Management

WordPress plugin vulnerabilities allow admin account takeover

(Credit: Bilal Ulker – stock.adobe.com)

Coverage from Bleeping Computer indicates that hackers are actively exploiting two critical authentication bypass vulnerabilities within the miniOrange SAML 2.0 Single Sign On plugin for WordPress. These flaws allow attackers to forge SAML responses and gain administrator access to affected websites.

The vulnerabilities, tracked as CVE-2026-61979 and CVE-2026-15981, can be chained together to bypass authentication. The first flaw allows an attacker to manipulate the plugin into treating a public key as a shared secret, enabling the forging of a valid signature. The second vulnerability then allows malformed signatures to pass validation. Security firm Patchstack reported that while fixes were released in July, the vendor's advisory only covered the free edition, leaving many users of the paid versions unaware and unpatched. This oversight has led to exploitation attempts, with a proof-of-concept exploit publicly available.

The attacks target the plugin's ability to integrate with identity platforms like Microsoft Entra ID, Okta, and Google Workspace, potentially impacting numerous businesses relying on these integrations for secure WordPress access. Website owners must manually update to patched versions, as the WordPress dashboard does not provide update warnings for paid plugin editions.

Source: Bleeping Computer

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds