Hackers are actively seeking to compromise WordPress websites by leveraging two newly addressed vulnerabilities found in a MiniOrange plugin. These flaws affect the SAML 2.0 Single Sign-On (SSO) plugin, a tool that facilitates single sign-on capabilities for WordPress platforms.
Identifying the Vulnerabilities
The vulnerabilities in question, labeled CVE-2026-61979 and CVE-2026-15981, pose a significant threat. The MiniOrange SAML 2.0 SSO plugin, which is installed on over 10,000 WordPress sites, is the focus. Although the free version’s usage is documented, data on the premium and enterprise editions remains unclear.
DigitalOcean, in collaboration with security experts at Patchstack, identified these vulnerabilities as critical authentication bypasses. These can allow unauthorized access to any WordPress account, potentially granting hackers administrative privileges.
Exploitation and Concerns
Patchstack describes the hacker attempts as opportunistic, rather than a targeted attack. The primary concern lies in the fact that despite the vulnerabilities being patched, users have not been sufficiently alerted to the risks. The free version’s update is noted as a bug fix in version 5.4.5, without clear emphasis on its security implications.
For premium users, the situation is more complex. The lack of notifications and a separate versioning system complicate the process of confirming that a site is secure. Users are required to manually update their plugins, heightening the risk of exploitation.
Implications for WordPress Users
Patchstack warns that the attackers are indiscriminately targeting sites with the plugin, regardless of the version or edition. This indiscriminate approach underscores the dangers of silent patches, where users remain unaware of potential threats while the attackers exploit unpatched vulnerabilities.
SecurityWeek has reached out to the plugin’s developer for further comments. As the situation develops, updates will be provided to keep the community informed.
With the growing number of WordPress sites facing potential security breaches, it is crucial for site administrators to ensure their plugins are up-to-date and to remain vigilant about emerging threats.
