← Back to Daily Briefing (Linux)

Two critical authentication bypass vulnerabilities, CVE-2026-61979 and CVE-2026-15981 (CVSS 9.8), were identified in the Xecurify miniOrange SAML 2.0 Single Sign On WordPress plugin. Attackers exploit flaws in SAML response processing and assertion data manipulation to circumvent Single Sign-On (SSO) logic, allowing unauthenticated actors to assume administrative identities and gain full control of affected WordPress installations. A significant intelligence gap occurred because the plugin's seven product editions share a single identifier (slug), causing premium versions to be omitted from early vulnerability databases while active exploitation was already occurring in the wild. Immediate manual patching and version auditing are required to mitigate risk.

  • Vulnerability Analysis: SAML Logic Flaws

    • CVE-2026-61979 allows unauthenticated privilege escalation via the manipulation of SAML assertion data.
    • CVE-2026-15981 enables direct authentication bypass through failures in the SAML response processing flow.
    • These vectors permit attackers to forge identities or bypass verification checks, effectively neutralizing SSO security controls.
  • Intelligence Gap: The "One Slug" Discrepancy

    • The plugin utilizes a single identifier (slug) across seven distinct product editions, including free and premium versions.
    • Early vulnerability database entries primarily tracked the free version, omitting paid editions from risk assessments.
    • Enterprise users relying on high-availability premium versions remained exposed due to a false sense of security provided by inaccurate database mappings.
  • Exploitation and Impact

    • Active exploitation was confirmed in the wild prior to widespread vendor notification and database coverage.
    • Successful attacks grant unauthenticated, full administrative access to the WordPress environment.
    • Compromised sites serve as potential jumping-off points for lateral movement into corporate identity providers and broader SSO infrastructures.
  • Remediation and Defensive Strategy

    • Prioritize manual patch verification across all editions, as automated updates may not cover all premium tiers.
    • Conduct immediate audits of all miniOrange SAML 2.0 SSO deployments to identify specific version numbers and patch levels.
    • Monitor SAML authentication logs for anomalous assertion patterns or unexpected administrative logins from unauthenticated sources.

Related posts

  1. Security Affairs — Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable
  2. bleepingcomputer.com — Hackers target WordPress sites in miniOrange auth bypass attacks
  3. SC Media — WordPress plugin vulnerabilities allow admin account takeover
  4. feeds.feedburner.com — Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
  5. Nvd
  6. App
  7. Patchstack
  8. Wordfence
  9. SecurityWeek — WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities

LINK COPIED TO CLIPBOARD