Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical miniOrange SAML Vulnerabilities Threaten WordPress

Critical miniOrange SAML Vulnerabilities Threaten WordPress

Posted on August 25, 2026 By CWS

Two significant security flaws have been identified in the miniOrange SAML 2.0 Single Sign-On plugin, posing a threat to WordPress sites. These vulnerabilities, known as CVE-2026-61979 and CVE-2026-15981, allow attackers to log in without authentication, potentially gaining administrator access. The flaws have a high CVSS score of 9.8 and have been exploited in real-world scenarios.

Understanding the Vulnerabilities

The weaknesses affect miniOrange’s SAML-based single sign-on software, which facilitates user authentication via an external Identity Provider. By exploiting the plugin’s SAML signature validation process, attackers can craft a fake authentication response, granting access to the WordPress admin panel.

The first flaw, CVE-2026-61979, involves a confusion in signature algorithms. The plugin erroneously accepts the signature algorithm defined in the SAML response, enabling an attacker to substitute the secure RSA-based verification with a less secure HMAC-SHA-1.

The second vulnerability, CVE-2026-15981, arises from improper handling of the openssl_verify() return value. Due to the plugin’s treatment of this result as a Boolean, a malformed signature causing an OpenSSL error could be incorrectly accepted as valid.

Investigations and Patches

DigitalOcean’s security team detected and blocked suspicious administrator session activities originating from untrusted networks. Their investigation confirmed the exploitation of these vulnerabilities in the miniOrange Standard edition 16.1.9. The issues were traced back to the plugin’s SAML validation logic.

miniOrange addressed CVE-2026-61979 in version 17.0.5 and CVE-2026-15981 in version 17.0.6 for the Standard edition. However, many installations using version 16.x may not receive automatic update notifications, necessitating manual updates to the patched version 17.x.

Implications for WordPress Administrators

This incident underscores the importance of thorough plugin version tracking, particularly across different commercial editions. Initially, public vulnerability records only covered the free edition, leaving paid versions vulnerable and absent from advisories.

Administrators are advised to manually verify their miniOrange product edition and ensure it is updated to the corrected release. Additionally, reviewing logs for administrator sessions from unusual IP addresses is recommended to detect potential breaches.

In light of these vulnerabilities, security teams must remain vigilant. The observed scanning attempts from various network addresses suggest broad exploitation efforts rather than targeted attacks. This case highlights the need for comprehensive threat intelligence and proactive security measures to prevent such incidents.

Cyber Security News Tags:CVE-2026-15981, CVE-2026-61979, Cybersecurity, DigitalOcean, identity verification, miniOrange flaws, OpenSSL, patch updates, plugin vulnerabilities, SAML vulnerabilities, threat detection, version tracking, vulnerability management, web security, WordPress security

Post navigation

Previous Post: First Car Head Unit Malware Links to Infamous Botnet
Next Post: Taiwan Charges Nine for Exporting AI Servers to China

Related Posts

Chinese MURKY PANDA Attacking Government and Professional Services Entities Chinese MURKY PANDA Attacking Government and Professional Services Entities Cyber Security News
Wealthsimple Data Breach Exposes Personal Information of Some Users Wealthsimple Data Breach Exposes Personal Information of Some Users Cyber Security News
Critical GitHub Token Flaw Risks User Security Critical GitHub Token Flaw Risks User Security Cyber Security News
Rockwell ControlLogix Ethernet Vulnerability Let Attackers Execute Remote Code Rockwell ControlLogix Ethernet Vulnerability Let Attackers Execute Remote Code Cyber Security News
NGINX Vulnerability Allows Remote Code Execution NGINX Vulnerability Allows Remote Code Execution Cyber Security News
Ukrainian Networks Launch Massive Brute-Force and Password-Spraying Campaigns Targeting SSL VPN and RDP Systems Ukrainian Networks Launch Massive Brute-Force and Password-Spraying Campaigns Targeting SSL VPN and RDP Systems Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Exploit Google Sites for Fake OpenAI Codex Downloads
  • Taiwan Charges Nine for Exporting AI Servers to China
  • Critical miniOrange SAML Vulnerabilities Threaten WordPress
  • First Car Head Unit Malware Links to Infamous Botnet
  • Oracle Server Vulnerability Actively Exploited: CISA Warning

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Exploit Google Sites for Fake OpenAI Codex Downloads
  • Taiwan Charges Nine for Exporting AI Servers to China
  • Critical miniOrange SAML Vulnerabilities Threaten WordPress
  • First Car Head Unit Malware Links to Infamous Botnet
  • Oracle Server Vulnerability Actively Exploited: CISA Warning

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark