08/27/2026🔴 Critical

Urgent Alert: Critical miniOrange SAML SSO Vulnerabilities Under Active Exploitation on WordPress

Security alert for businesses running WordPress with miniOrange SAML 2.0 SSO plugin. Attackers are actively exploiting flaws to bypass authentication.

⚠️ This vulnerability is being actively exploited in the wild — patch immediately.
🔴 Critical✅ Official patch available

Affected platforms

Urgent Alert: Critical miniOrange SAML SSO Vulnerabilities Under Active Exploitation on WordPress

As organizations increasingly rely on Single Sign-On (SSO) solutions to streamline user experience and centralize identity management, a critical security alert has been issued. This week, cybersecurity researchers detected active, real-world exploitation targeting WordPress websites running the miniOrange SAML 2.0 SSO plugin. This incident serves as a stark reminder that even security-focused tools can become a primary attack vector if they are not continuously monitored and promptly updated.

Executive summary

  • The miniOrange SAML 2.0 SSO plugin for WordPress is affected by two severe vulnerabilities (CVE-2026-15981 and CVE-2026-61979) with a maximum CVSS score of 9.8/10.
  • Unauthenticated attackers can bypass authentication entirely and log in as any existing user, including administrators, without knowing the password.
  • Active exploitation has been observed in the wild, characterized by automated, opportunistic scanning targeting exposed websites.
  • The developer released a 'silent patch' without prominent security advisories, leaving many paid and enterprise edition users unaware of the critical risk.
  • Immediate action: Update the plugin to the latest version (Standard edition 17.0.6 or higher) and audit system access logs for anomalous sessions.

What happened?

Security researchers have observed active exploitation attempts targeting two recently patched vulnerabilities in the miniOrange SAML 2.0 SSO plugin for WordPress. This plugin is widely used by enterprises to integrate WordPress sites with identity providers like Okta, Azure AD, and OneLogin. The most critical flaw, CVE-2026-15981 (CVSS 9.8), allows complete authentication bypass. The second flaw, CVE-2026-61979 (CVSS 8.1), involves privilege escalation due to signature algorithm confusion. Compounding the risk, the developer patched the vulnerabilities without issuing clear security advisories for paid editions, creating a dangerous 'silent patch' scenario where many enterprise sites remain unpatched.

How the attack works at a high level

The critical CVE-2026-15981 vulnerability stems from a classic loose comparison flaw in PHP's handling of cryptographic signature verification. Specifically, the plugin's signature validation function performs a loose boolean check on the raw integer returned by PHP's openssl_verify() function. This function returns 1 for a valid signature, 0 for an invalid signature, and -1 in case of an internal error. Due to the loose check, the error value of -1 is evaluated as truthy (true). An attacker can exploit this by sending a crafted SAMLResponse containing a deliberately malformed signature that triggers an OpenSSL processing error. The plugin interprets this error as a successful verification, bypassing authentication entirely and granting administrative access.

Why this is a business risk

For any business, a website is more than just a digital storefront; it is a gateway to customer data, transactional systems, and internal operations. Allowing an attacker to bypass authentication and gain full administrative control poses severe business risks. This includes massive customer data breaches that violate privacy regulations, website defacement, ransomware injection, and malicious code deployment. Furthermore, compromised sites are often blacklisted by search engines like Google, causing catastrophic damage to SEO rankings, brand reputation, and online revenue.

What businesses should do in the next 24–72 hours

  • Update immediately: Upgrade the miniOrange SAML 2.0 SSO plugin to version 17.0.6 or higher for the Standard edition, or contact the vendor to secure the latest patched version for Premium/Enterprise editions.
  • Audit administrator accounts: Review the WordPress user list to identify any unauthorized admin accounts or unexpected changes in user roles.
  • Analyze access logs: Search web server logs for unusual SAMLResponse payloads or administrator login events originating from untrusted external IP addresses.
  • Deploy WAF rules: Enable specific Web Application Firewall (WAF) rules on platforms like Cloudflare or Wordfence to block automated SAML bypass exploit attempts.

Other notable enterprise security risks this week

Beyond WordPress, two other critical enterprise vulnerabilities emerged this week that demand immediate attention: First, CVE-2026-72898 (CVSS 10.0) is a critical unauthenticated SQL injection vulnerability in self-hosted Metabase business intelligence instances, allowing attackers to manipulate databases and gain admin access. Second, CVE-2026-18963 (CVSS 9.1) affects Keycloak identity and access management servers, enabling unauthenticated remote attackers to take over any user account by bypassing the Action Token requirement during password resets.

Long-term lessons for CMS and digital infrastructure security

This incident highlights a growing and concerning trend: 'Silent Patching,' where vendors quietly fix critical vulnerabilities without prominent public disclosure. To mitigate this risk, businesses must shift from reactive patching to proactive vulnerability management. This involves maintaining an active inventory of all digital assets, conducting regular manual audits of critical authentication components, and implementing continuous monitoring. Adopting a Zero Trust architecture ensures that even if an authentication mechanism is bypassed, lateral movement is restricted and anomalies are quickly contained.

How Hanoi Byte can help

If your business relies on WordPress, a custom CMS, or cloud-based digital infrastructure, Hanoi Byte can help you assess risks, modernize your systems, and build a practical security and maintenance roadmap. We offer expert services in digital strategy, cloud optimization, custom software development, and proactive system maintenance to ensure your operations remain secure, scalable, and resilient. Contact Hanoi Byte today to start a conversation about securing and transforming your digital enterprise.

Contact Us