Critical miniOrange SAML SSO flaws let attackers hijack WordPress admin accounts
Two critical authentication bypass vulnerabilities, tracked as CVE-2026-61979 and CVE-2026-15981, have been discovered in the miniOrange SAML 2.0 Single Sign On plugin across seven WordPress editions. The flaws allow attackers to forge SAML responses and obtain valid WordPress administrator session cookies without needing a password, MFA, or access to identity provider credentials. The first vulnerability exploits algorithm confusion by using the RSA public key as an HMAC secret, while the second abuses PHP's openssl_verify() returning -1 on error, which the plugin incorrectly treats as a successful verification. Real-world exploitation was detected by DigitalOcean, where an external actor obtained an admin session cookie, though further damage was prevented by network-level restrictions on the WordPress admin panel. Opportunistic scans targeting miniOrange SSO endpoints have been observed from multiple IP regions, indicating widespread, indiscriminate attack attempts.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in