Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Hackers target WordPress sites in miniOrange auth bypass attacks

    August 24, 2026

    How a Network of Volunteers Is Liberating Critical Court Records for Everyone

    August 24, 2026

    Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

    August 24, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Hackers target WordPress sites in miniOrange auth bypass attacks
    News

    Hackers target WordPress sites in miniOrange auth bypass attacks

    adminBy adminAugust 24, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Hackers target WordPress sites in miniOrange auth bypass attacks

    Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators.

    The miniOrange SAML SSO plugin turns a WordPress site into a SAML service provider, letting users log in through corporate identity platforms such as Microsoft Entra ID, Okta, Google Workspace, or OneLogin instead of separate WordPress credentials.

    Created by Xecurify, miniOrange is a family of seven plugins, with a free version that has 10,000 downloads and 30,000 customers for the other six.

    image

    The two vulnerabilities observed in exploitation attempts are tracked as CVE-2026-61979 and CVE-2026-15981 and can be chained together to bypass authentication.

    Because the miniOrange SAML SSO plugin accepts the signature algorithm from incoming SAML responses instead of enforcing the configured one, an attacker can leverage CVE-2026-61979 to select HMAC-SHA1. This causes the plugin to treat the RSA public key from the identity provider (IdP) as the shared secret.

    Since the public key is known, the attacker can forge a signature that the plugin accepts as authentic.

    The second security issue, CVE-2026-15981, causes the plugin to treat an OpenSSL verification error (-1) as a successful result, allowing malformed signatures to pass validation.

    According to security firm Patchstack, the two vulnerabilities were publicly disclosed and fixed in July. However, the vendor’s advisory covered only the free edition, leaving the six paid editions without an alert, even though fixes were provided for those too.

    The following versions addressed the two flaws:

    1. Free, single site – 5.4.5
    2. Premium, single site – 13.0.4
    3. Standard, single site – 17.06
    4. Premium/Enterprise/All-Inclusive, multisite – 20.2.8
    5. Enterprise/All-Inclusive, single site – 26.0.3
    6. VIP, single site – 32.0.8
    7. VIP, multisite – 35.0.7

    Failing to disclose the risk across all versions of the plugin reportedly led many sites running the paid editions to take no action, creating an opportunity for threat actors to exploit the two vulnerabilities.

    Patchstack reports that, on August 16, DigitalOcean blocked an anomalous WordPress administrator session originating outside its trusted network.

    The investigation showed that attackers have chained the two flaws to obtain an admin session cookie through the Standard edition plugin in version 16.1.9.

    Patchstack’s data shows that exploitation attempts and opportunistic scanning are underway, launched from six IP addresses across Europe, Africa, and the United States.

    A proof-of-concept (PoC) exploit targeting the free edition is also publicly available, so the pace of attacks could increase at any time.

    Patchstack warns that the WordPress administrator dashboard will not show update warnings for the paid versions of the plugin, so website owners must manually upgrade to a patched release.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleHow a Network of Volunteers Is Liberating Critical Court Records for Everyone
    admin
    • Website

    Related Posts

    News

    How a Network of Volunteers Is Liberating Critical Court Records for Everyone

    August 24, 2026
    News

    Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

    August 24, 2026
    News

    Exploiting SharePoint: CVE-2026-55040 and CVE-2026-63520 RCE Chain | Blog

    August 24, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202640 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202640 Views
    Our Picks

    Hackers target WordPress sites in miniOrange auth bypass attacks

    August 24, 2026

    How a Network of Volunteers Is Liberating Critical Court Records for Everyone

    August 24, 2026

    Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

    August 24, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.