Hackers Target WordPress Sites in miniOrange Authentication Bypass Attacks

Date:

In recent weeks, hackers have escalated their attacks on WordPress sites by exploiting two critical authentication bypass vulnerabilities found in the miniOrange SAML 2.0 Single Sign-On plugin. This plugin, designed to enable users to log in through corporate identity platforms, has been targeted specifically to forge SAML responses and gain unauthorized administrator access, posing a significant risk to website security.

Understanding the Vulnerabilities

The vulnerabilities are identified as CVE-2026-61979 and CVE-2026-15981. They allow attackers to bypass authentication mechanisms effectively. The first, CVE-2026-61979, permits attackers to manipulate the signing algorithm from incoming SAML responses. This flaw results in the plugin treating the RSA public key from the identity provider as a shared secret, which can be exploited to forge an acceptable signature.

The second vulnerability, CVE-2026-15981, exacerbates this issue by allowing malformed signatures to pass validation due to improper handling of OpenSSL verification errors. Together, these flaws create a pathway for malicious actors to gain access to administrative privileges without the necessary credentials.

Impact on miniOrange’s User Base

miniOrange, developed by Xecurify, is a suite of plugins that has garnered significant attention, boasting around 30,000 customers across its offerings. While the vulnerabilities were publicly disclosed and patched in July, the advisory for fixes primarily covered the free version, leaving users of the paid versions unaware and unprotected. This oversight has opened a door for exploitation, as many administrators may not realize the risks involved or the urgent need to update their systems.

Various versions of the plugin addressed these vulnerabilities, including both the free and premium editions. However, the lack of a comprehensive alert system for all editions has left many vulnerable, with Patchstack reporting attempts to exploit these issues actively across multiple regions, including Europe, Africa, and the United States.

Evidence of Active Exploitation

Patchstack recently highlighted that on August 16, DigitalOcean detected unusual WordPress administrator sessions originating from outside trusted networks. Further investigations revealed that attackers exploited the flaws in the Standard edition of the plugin, specifically version 16.1.9, to obtain an admin session cookie. This underscores the urgent need for website administrators to ensure their installations are updated to the latest versions, as exploitation attempts are ongoing, with public proof-of-concept exploits available.

What’s Next for WordPress Administrators?

As the situation unfolds, website owners using miniOrange plugins must remain vigilant. Patchstack warns that the WordPress admin dashboard for the paid versions may not display update alerts, necessitating manual upgrades to secure releases.

To mitigate risks:

  • Regularly check for updates and apply patches to all versions of the miniOrange plugin immediately.
  • Monitor website traffic for unusual activity that could indicate exploitation attempts.
  • Consider implementing additional security measures, such as web application firewalls, to protect against unauthorized access.

Finally, keeping informed about security developments related to WordPress and its extensive ecosystem of plugins is crucial in maintaining a secure online presence.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Share post:

spot_imgspot_img

Popular

More like this
Related

Critical PHP Object Injection Vulnerability Found in GiveWP Plugin

A recently discovered vulnerability in the GiveWP plugin poses...

AI Advances Strengthen Cybersecurity: Wordfence Unveils Critical Vulnerability Discovery

Wordfence has revealed significant advancements in its incorporation of...

Critical Unauthenticated Account Takeover Vulnerability Found in TranslatePress Plugin

On August 11, 2026, a significant security vulnerability was...

ManageWP Achieves Unprecedented Security with Patchstack, Blocking 11.9 Million Threats

ManageWP, in collaboration with Patchstack, has made significant strides...