INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Two CVSS 9.8 Auth Bypasses Exploited in miniOrange SAML Plugin
| 2026-08-25 08:34 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The threat landscape is increasingly complex, with attackers exploiting vulnerabilities in various software applications to gain unauthorized access and manipulate sensitive information. MiniOrange SSO endpoints, a critical component of online security systems, have been identified as a target by malicious actors. These entities are actively scanning six IP addresses from Belgium, Nigeria, the U.S., and Germany, indicating a high level of sophistication and intent. The use of defense in depth measures has proven ineffective against these attackers, who have successfully bypassed authentication mechanisms using CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin. This vulnerability allows unauthenticated attackers to forge SAML authentication responses, effectively gaining access to sensitive information. As a result, organizations must prioritize patching and updating vulnerable software applications, including those used by MiniOrange, to mitigate this threat.
Technical Mitigations AI-generated
* Manual patch required: The CVE-2026-61979 and CVE-2026-15981 vulnerabilities require a manual update to the miniOrange SAML WordPress plugin to fix.
* Use of HMAC-SHA1 algorithm: The first vulnerability allows an attacker to forge a SAML authentication response by setting the HMAC-SHA1 algorithm to use the identity provider's RSA public key as the HMAC secret. This can be mitigated by using a more secure signature algorithm, such as HMAC-SHA256 or SHA-512.
* Incorrect handling of OpenSSL errors: The second vulnerability allows an attacker to send a specially crafted signature that causes an OpenSSL error, making it appear valid. This can be mitigated by properly handling OpenSSL errors and returning the correct result code (1 for valid, 0 for invalid, -1 for error).
* Secure authentication practices: To prevent similar attacks in the future, organizations should ensure that their WordPress installations are using secure authentication practices, such as:
* Using a more secure signature algorithm
* Properly handling OpenSSL errors and returning correct result codes
* Implementing rate limiting on login attempts to prevent brute-force attacks
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
162.243.•••.•••
207.211.•••.•••
102.91.•••.•••
64.225.•••.•••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-61979CVE-2026-61979
CVE-2026-15981CVE-2026-15981
Target & Sectors
EUROPE
EUROPE
BENELUX
BENELUX
NORTH_AMERICA
NORTH_AMERICA
DACH
DACH
AFRICA
AFRICA
Incident Timeline
August 16
DigitalOcean blocked an anomalous WordPress administrator session on August 16.
Aug 25, 2026
Attackers exploited an unauthenticated privilege escalation vulnerability in WordPress, specifically the `miniOrange SAML` flaw, by submitting a crafted SAMLResponse containing an attacker-controlled NameID and a deliberately malformed signature value that triggered an OpenSSL processing error.
Click on any entity below to view its context and source!
organisation
CVE-2026-15981
An unauthenticated privilege escalation vulnerability stemming from signature algorithm confusion (Fixed in version 17.0.5 for the Standard edition)
CVE-2026-15981
(CVSS score: 9.8) -
infrastructure
17.0.5
An unauthenticated privilege escalation vulnerability stemming from signature algorithm confusion (Fixed in version 17.0.5 for the Standard edition)
CVE-2026-15981
(CVSS score: 9.8) -
infrastructure
9.8
An unauthenticated privilege escalation vulnerability stemming from signature algorithm confusion (Fixed in version 17.0.5 for the Standard edition)
CVE-2026-15981
(CVSS score: 9.8) -
infrastructure
17.0.6
An authentication bypass vulnerability stemming from accepting malformed signatures as valid (Fixed in version 17.0.6 for the Standard edition)
"This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's openssl_verify(), causing an error return value of -1 to be evaluated as truthy and therefore treated as a successful signature verification," according to a description of CVE-2026-15981 on CVE.org.
organisation
PHP
An authentication bypass vulnerability stemming from accepting malformed signatures as valid (Fixed in version 17.0.6 for the Standard edition)
"This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's openssl_verify(), causing an error return value of -1 to be evaluated as truthy and therefore treated as a successful signature verification," according to a description of CVE-2026-15981 on CVE.org.
organisation
-1
An authentication bypass vulnerability stemming from accepting malformed signatures as valid (Fixed in version 17.0.6 for the Standard edition)
"This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's openssl_verify(), causing an error return value of -1 to be evaluated as truthy and therefore treated as a successful signature verification," according to a description of CVE-2026-15981 on CVE.org.
organisation
CVE-2026
An authentication bypass vulnerability stemming from accepting malformed signatures as valid (Fixed in version 17.0.6 for the Standard edition)
"This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's openssl_verify(), causing an error return value of -1 to be evaluated as truthy and therefore treated as a successful signature verification," according to a description of CVE-2026-15981 on CVE.org.
organisation
CVE.org
An authentication bypass vulnerability stemming from accepting malformed signatures as valid (Fixed in version 17.0.6 for the Standard edition)
"This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP's openssl_verify(), causing an error return value of -1 to be evaluated as truthy and therefore treated as a successful signature verification," according to a description of CVE-2026-15981 on CVE.org.
organisation
IP
The scanning activity has been recorded from the following IP addresses -
207.211.214.41
79.127.224.14
102.91.71.83
162.243.116.148
84.201.6.54
64.225.25.188
"The spread suggests opportunistic scanning rather than a targeted campaign," Patchstack added.
organisation
SAMLResponse
"This makes it possible for unauthenticated attackers to log in as any existing WordPress user, including administrators, by submitting a crafted SAMLResponse containing an attacker-controlled NameID and a deliberately malformed signature value that triggers an OpenSSL processing error — bypassing verification entirely and resulting in wp_set_auth_cookie() being called for the targeted account.
organisation
NameID
"This makes it possible for unauthenticated attackers to log in as any existing WordPress user, including administrators, by submitting a crafted SAMLResponse containing an attacker-controlled NameID and a deliberately malformed signature value that triggers an OpenSSL processing error — bypassing verification entirely and resulting in wp_set_auth_cookie() being called for the targeted account.
organisation
Patchstack
"The attacker had already used the bypass to obtain a WordPress admin session cookie, but was stalled because the admin panel operations themselves sat restricted behind the trusted network," Patchstack said.
organisation
PoC
"
WordPress site owners are advised to apply the latest fixes to stay protected, especially given the availability of a proof-of-concept (PoC) code that allows attackers to chain the flaws to obtain admin privileges and take control of susceptible sites.
2026/08/25
Attackers exploited two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that made it possible for an attacker to sign in as any WordPress user, including administrators.
Click on any entity below to view its context and source!
organisation
CVE-2026
Both CVE-2026-61979 and CVE-2026-15981 allow an unauthenticated attacker to forge a SAML authentication response and arrive in
/wp-admin
as any existing user, including administrators.
The two vulnerabilities observed in exploitation attempts are tracked as CVE-2026-61979 and CVE-2026-15981 and can be chained together to bypass authentication.
organisation
PHP
CVE-2026-15981 is a PHP bug caused by incorrectly handling different types of values.
organisation
CVE-2026-61979
The two vulnerabilities observed in exploitation attempts are tracked as CVE-2026-61979 and CVE-2026-15981 and can be chained together to bypass authentication.
CVE-2026-61979 is an algorithm confusion flaw.
organisation
CVSS 9.8 Auth Bypasses
Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable.
organisation
-1
In PHP,
-1 counts as true
.
organisation
IP
Attackers are actively scanning miniOrange SSO endpoints from six IP addresses in Belgium, Nigeria, the U.S. and Germany.
Patchstack’s data shows that exploitation attempts and opportunistic scanning are underway, launched from six IP addresses across Europe, Africa, and the United States.
organisation
Attackers Target miniOrange SAML Flaws
Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access.
organisation
Vulnerability / Web Security
Ravie Lakshmanan
Aug 25, 2026
Vulnerability / Web Security
Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators.
organisation
WordPress
Ravie Lakshmanan
Aug 25, 2026
Vulnerability / Web Security
Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators.
Two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On WordPress plugin, both rated CVSS 9.8, are under active exploitation.
Hackers target WordPress sites in miniOrange auth bypass attacks.
organisation
The Blue Report 2026
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
organisation
Patchstack
DigitalOcean then traced both bugs to specific lines of code in the plugin and its bundled XML security library, confirmed the affected version ranges across all seven paid editions (which miniOrange had not published anywhere), wrote two narrowly scoped hotfixes to buy time, and handed the full analysis to Patchstack for publication.
According to
security firm Patchstack
, the two vulnerabilities were publicly disclosed and fixed in July.
organisation
XML
DigitalOcean then traced both bugs to specific lines of code in the plugin and its bundled XML security library, confirmed the affected version ranges across all seven paid editions (which miniOrange had not published anywhere), wrote two narrowly scoped hotfixes to buy time, and handed the full analysis to Patchstack for publication.
organisation
PoC
A proof-of-concept (PoC) exploit targeting the free edition is also publicly available, so the pace of attacks could increase at any time.
infrastructure
5.4.5
“While that record is correct, when you apply it to the slug, every paid install carries a higher version number than 5.4.5, so every paid install reads as already patched.”
The following versions addressed the two flaws:
Free, single site – 5.4.5
Premium, single site – 13.0.4
Standard, single site – 17.06
Premium/Enterprise/All-Inclusive, multisite – 20.2.8
Enterprise/All-Inclusive, single site – 26.0.3
VIP, single site – 32.0.8
VIP, multisite – 35.0.7
Failing to disclose the risk across all versions of the plugin reportedly led many sites running the paid editions to take no action, creating an opportunity for threat actors to exploit the two vulnerabilities.
infrastructure
13.0.4
The following versions addressed the two flaws:
Free, single site – 5.4.5
Premium, single site – 13.0.4
Standard, single site – 17.06
Premium/Enterprise/All-Inclusive, multisite – 20.2.8
Enterprise/All-Inclusive, single site – 26.0.3
VIP, single site – 32.0.8
VIP, multisite – 35.0.7
Failing to disclose the risk across all versions of the plugin reportedly led many sites running the paid editions to take no action, creating an opportunity for threat actors to exploit the two vulnerabilities.
infrastructure
17.06
The following versions addressed the two flaws:
Free, single site – 5.4.5
Premium, single site – 13.0.4
Standard, single site – 17.06
Premium/Enterprise/All-Inclusive, multisite – 20.2.8
Enterprise/All-Inclusive, single site – 26.0.3
VIP, single site – 32.0.8
VIP, multisite – 35.0.7
Failing to disclose the risk across all versions of the plugin reportedly led many sites running the paid editions to take no action, creating an opportunity for threat actors to exploit the two vulnerabilities.
infrastructure
20.2.8
The following versions addressed the two flaws:
Free, single site – 5.4.5
Premium, single site – 13.0.4
Standard, single site – 17.06
Premium/Enterprise/All-Inclusive, multisite – 20.2.8
Enterprise/All-Inclusive, single site – 26.0.3
VIP, single site – 32.0.8
VIP, multisite – 35.0.7
Failing to disclose the risk across all versions of the plugin reportedly led many sites running the paid editions to take no action, creating an opportunity for threat actors to exploit the two vulnerabilities.
infrastructure
26.0.3
The following versions addressed the two flaws:
Free, single site – 5.4.5
Premium, single site – 13.0.4
Standard, single site – 17.06
Premium/Enterprise/All-Inclusive, multisite – 20.2.8
Enterprise/All-Inclusive, single site – 26.0.3
VIP, single site – 32.0.8
VIP, multisite – 35.0.7
Failing to disclose the risk across all versions of the plugin reportedly led many sites running the paid editions to take no action, creating an opportunity for threat actors to exploit the two vulnerabilities.
infrastructure
32.0.8
The following versions addressed the two flaws:
Free, single site – 5.4.5
Premium, single site – 13.0.4
Standard, single site – 17.06
Premium/Enterprise/All-Inclusive, multisite – 20.2.8
Enterprise/All-Inclusive, single site – 26.0.3
VIP, single site – 32.0.8
VIP, multisite – 35.0.7
Failing to disclose the risk across all versions of the plugin reportedly led many sites running the paid editions to take no action, creating an opportunity for threat actors to exploit the two vulnerabilities.
infrastructure
35.0.7
The following versions addressed the two flaws:
Free, single site – 5.4.5
Premium, single site – 13.0.4
Standard, single site – 17.06
Premium/Enterprise/All-Inclusive, multisite – 20.2.8
Enterprise/All-Inclusive, single site – 26.0.3
VIP, single site – 32.0.8
VIP, multisite – 35.0.7
Failing to disclose the risk across all versions of the plugin reportedly led many sites running the paid editions to take no action, creating an opportunity for threat actors to exploit the two vulnerabilities.
organisation
Premium/Enterprise/All-Inclusive
The following versions addressed the two flaws:
Free, single site – 5.4.5
Premium, single site – 13.0.4
Standard, single site – 17.06
Premium/Enterprise/All-Inclusive, multisite – 20.2.8
Enterprise/All-Inclusive, single site – 26.0.3
VIP, single site – 32.0.8
VIP, multisite – 35.0.7
Failing to disclose the risk across all versions of the plugin reportedly led many sites running the paid editions to take no action, creating an opportunity for threat actors to exploit the two vulnerabilities.
organisation
20.2.8
Enterprise/All-Inclusive
The following versions addressed the two flaws:
Free, single site – 5.4.5
Premium, single site – 13.0.4
Standard, single site – 17.06
Premium/Enterprise/All-Inclusive, multisite – 20.2.8
Enterprise/All-Inclusive, single site – 26.0.3
VIP, single site – 32.0.8
VIP, multisite – 35.0.7
Failing to disclose the risk across all versions of the plugin reportedly led many sites running the paid editions to take no action, creating an opportunity for threat actors to exploit the two vulnerabilities.
infrastructure
16.1.9
“Therefore, any WordPress site that was running a vulnerable version like 16.1.9 reported it as patched, along with every other (13.x, 20.x, 26.x, 32.x, and 35.x) vulnerable version.”
The investigation showed that attackers have chained the two flaws to obtain an admin session cookie through the Standard edition plugin in version 16.1.9.
organisation
HMAC-SHA1
An attacker sets that algorithm to HMAC-SHA1, which causes the plugin to use the identity provider’s RSA public key as the HMAC secret.
organisation
HMAC
An attacker sets that algorithm to HMAC-SHA1, which causes the plugin to use the identity provider’s RSA public key as the HMAC secret.
organisation
RSA
The RSA public key is, by definition, public.
This causes the plugin to treat the RSA public key from the identity provider (IdP) as the shared secret.
organisation
IdP
This causes the plugin to treat the RSA public key from the identity provider (IdP) as the shared secret.
organisation
WordPress.org
When the public advisories were written, they covered only the Free edition, which is the one anyone can download from WordPress.org.
organisation
IPs
If you can’t update immediately, two narrowly scoped hotfixes covering both CVEs are published there alongside the IPs to check in your logs for prior exploitation attempts.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, miniOrange SAML WordPress Plugin)
organisation
Microsoft Entra ID
The miniOrange SAML SSO plugin turns a WordPress site into a SAML service provider, letting users log in through corporate identity platforms such as Microsoft Entra ID, Okta, Google Workspace, or OneLogin instead of separate WordPress credentials.
organisation
OneLogin
The miniOrange SAML SSO plugin turns a WordPress site into a SAML service provider, letting users log in through corporate identity platforms such as Microsoft Entra ID, Okta, Google Workspace, or OneLogin instead of separate WordPress credentials.
infrastructure
10,000 downloads
Created by Xecurify, miniOrange is a family of seven plugins, with a free version that has
10,000 downloads
and
30,000 customers
for the other six.
victims
30,000 customers
Created by Xecurify, miniOrange is a family of seven plugins, with a free version that has
10,000 downloads
and
30,000 customers
for the other six.
Tactical Metrics
Metrics
infrastructure
17.0.5
Software Version
Click for context!
An unauthenticated privilege escalation vulnerability stemming from signature algorithm confusion (Fixed in version 17.0.5 for the Standard edition)
CVE-2026-15981
(CVSS score: 9.8) -
Metrics
infrastructure
9.8
Software Version
An unauthenticated privilege escalation vulnerability stemming from signature algorithm confusion (Fixed in version 17.0.5 for the Standard edition)
CVE-2026-15981
(CVSS score: 9.8) -
Metrics
infrastructure
17.0.6
Software Version
An authentication bypass vulnerability stemming from accepting malformed signatures as valid (Fixed in version 17.0.6 for the Standard edition)
"This is due to the mo_saml_validate_signature() function performing a loose boolean check on the ra…
Metrics
infrastructure
5.4.5
Software Version
“While that record is correct, when you apply it to the slug, every paid install carries a higher version number than 5.4.5, so every paid install reads as already patched.”
The following versions addressed the two flaws:
Free, single site – 5.4.5
Premium, single site – 13.0.4
Standard, single site – 17.06
Premium/Enterprise/All-Inclusive, multisite – 20.2.8
Enterprise/All-Inclusive, single site – 26.0.3
VI…
Metrics
infrastructure
16.1.9
Software Version
“Therefore, any WordPress site that was running a vulnerable version like 16.1.9 reported it as patched, along with every other (13.x, 20.x, 26.x, 32.x, and 35.x) vulnerable version.”
The investigation showed that attackers have chained the two flaws to obtain an admin session cookie through the Standard edition plugin in version 16.1.9.
Metrics
infrastructure
13.0.4
Software Version
The following versions addressed the two flaws:
Free, single site – 5.4.5
Premium, single site – 13.0.4
Standard, single site – 17.06
Premium/Enterprise/All-Inclusive, multisite – 20.2.8
Enterprise/All-Inclusive, single site – 26.0.3
VI…
Metrics
infrastructure
17.06
Software Version
…ing versions addressed the two flaws:
Free, single site – 5.4.5
Premium, single site – 13.0.4
Standard, single site – 17.06
Premium/Enterprise/All-Inclusive, multisite – 20.2.8
Enterprise/All-Inclusive, single site – 26.0.3
VIP, single…
Metrics
infrastructure
20.2.8
Software Version
…ite – 5.4.5
Premium, single site – 13.0.4
Standard, single site – 17.06
Premium/Enterprise/All-Inclusive, multisite – 20.2.8
Enterprise/All-Inclusive, single site – 26.0.3
VIP, single site – 32.0.8
VIP, multisite – 35.0.7
Failing to d…
Metrics
infrastructure
26.0.3
Software Version
…ndard, single site – 17.06
Premium/Enterprise/All-Inclusive, multisite – 20.2.8
Enterprise/All-Inclusive, single site – 26.0.3
VIP, single site – 32.0.8
VIP, multisite – 35.0.7
Failing to disclose the risk across all versions of the plugi…
Metrics
infrastructure
32.0.8
Software Version
…Premium/Enterprise/All-Inclusive, multisite – 20.2.8
Enterprise/All-Inclusive, single site – 26.0.3
VIP, single site – 32.0.8
VIP, multisite – 35.0.7
Failing to disclose the risk across all versions of the plugin reportedly led many sites…
Metrics
infrastructure
35.0.7
Software Version
…clusive, multisite – 20.2.8
Enterprise/All-Inclusive, single site – 26.0.3
VIP, single site – 32.0.8
VIP, multisite – 35.0.7
Failing to disclose the risk across all versions of the plugin reportedly led many sites running the paid editions…
Metrics
infrastructure
10,000
Downloads
Created by Xecurify, miniOrange is a family of seven plugins, with a free version that has
10,000 downloads
and
30,000 customers
for the other six.
Metrics
victims
30,000
Customers
Created by Xecurify, miniOrange is a family of seven plugins, with a free version that has
10,000 downloads
and
30,000 customers
for the other six.
Intelligence Sources
Security Affairs
2026-08-25
BleepingComputer
2026-08-24
Hackers target WordPress sites in miniOrange auth bypass attacks
BleepingComputer
The Hacker News
2026-08-25
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-26T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
28x
organisation
Identified Entity
CVE-2026-15981
entity
11x
infrastructure
Software Version
17.0.5
version
4x
target region
Target Country
Belgium
country
3x
timeline
Temporal Reference
Aug 25, 2026
date
2x
vulnerability
Exploited CVE
CVE-2026-15981
cve
2x
general metric
Aug
25
aug
2x
target region
Target Region
AFRICA
region
Contextual Telemetry
Context Block
12 METRICS
tactic
Cyber Operation Type
Privilege Escalation
tactic
general metric
Unauthenticated Escalation Vulnerability
10
unauthenticated escalation vulnerability
general metric
Score
8
score
general metric
Single Sign
2
single sign
industry
Targeted Sector
Defense
sector
vulnerability
CVSS Score
10
score
general metric
Results
1
results
general metric
Signature
0
signature
general metric
All Inclusive
17
all inclusive
general metric
Simulations
338,000,000
simulations
infrastructure
Downloads
10,000
downloads
victims
Customers
30,000
customers
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.