Affected Systems
miniOrange SAML 2.0 Single Sign On plugin for WordPress. Vulnerable versions: Free <5.4.5, Premium single-site <13.0.4, Standard single-site <17.06, Premium/Enterprise/All-Inclusive multisite <20.2.8, Enterprise/All-Inclusive single-site <26.0.3, VIP single-site <32.0.8, VIP multisite <35.0.7. Affects 10,000+ free installs and 30,000 paid customers using the plugin for SAML-based authentication with Microsoft Entra ID, Okta, Google Workspace, or OneLogin.
Exploitation Status
Active exploitation confirmed since August 16, 2026. Attacks observed from six IP addresses across Europe, Africa, and United States. Public PoC exploit available for free edition. DigitalOcean blocked anomalous admin sessions created via CVE-2026-61979 and CVE-2026-15981 chain targeting Standard edition v16.1.9. Opportunistic scanning underway.
Business Impact
Attackers can forge SAML responses and bypass authentication to gain WordPress administrator access without valid credentials. CVE-2026-61979 allows forcing HMAC-SHA1 algorithm and treating RSA public key as shared secret; CVE-2026-15981 treats OpenSSL error (-1) as successful validation. Chaining both flaws enables complete site takeover. Paid editions lack update notifications in WordPress dashboard, leaving many sites unpatched despite fixes released in July 2026. High risk for organizations using SAML SSO for corporate identity integration.
Urgency
🔴 Immediate
Recommended Actions
- Immediately upgrade miniOrange SAML SSO plugin to patched versions: Free 5.4.5+, Premium single-site 13.0.4+, Standard 17.06+, Premium/Enterprise/All-Inclusive multisite 20.2.8+, Enterprise/All-Inclusive single-site 26.0.3+, VIP single-site 32.0.8+, VIP multisite 35.0.7+
- Manually check paid edition versions via plugin settings or file system—WordPress dashboard does not show update warnings for paid versions
- Review WordPress administrator accounts created since July 2026 for unauthorized entries; check access logs for SAML authentication anomalies
- Monitor for suspicious admin sessions originating from unexpected geographic locations or IP ranges outside trusted networks
- Consider temporarily disabling miniOrange SAML SSO plugin if immediate patching is not feasible and revert to native WordPress authentication until upgrade is complete
