Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Exploits Targeting miniOrange SAML Vulnerabilities in WordPress

Exploits Targeting miniOrange SAML Vulnerabilities in WordPress

Posted on August 25, 2026 By CWS

Recent findings have uncovered that malicious actors are attempting to exploit critical vulnerabilities in the Xecurify miniOrange SAML 2.0 Single Sign On plugin. These vulnerabilities can allow unauthorized individuals to gain access to WordPress accounts, including those with administrative privileges. The security flaws were disclosed by Patchstack, highlighting the potential risk to WordPress users.

Details of the Vulnerabilities

The flaws identified are serious authentication bypass issues, specifically CVE-2026-61979 and CVE-2026-15981. The first flaw, CVE-2026-61979, scores an 8.1 on the CVSS scale and involves privilege escalation due to confusion in the signature algorithm. This issue has been addressed in version 17.0.5 of the plugin’s Standard edition.

More severe is CVE-2026-15981, which holds a CVSS score of 9.8. This vulnerability occurs when malformed signatures are incorrectly verified as valid. The problem arises from the mo_saml_validate_signature() function’s improper handling of the return value from PHP’s openssl_verify(), where an error is mistakenly treated as a successful verification. The fix for this was released in version 17.0.6 of the plugin.

Potential Impact and Exploitation

The vulnerabilities allow attackers to craft SAML responses with manipulated signatures that the plugin accepts as legitimate. This can lead to unauthorized logins under any existing WordPress user accounts, including administrators. The exploit involves sending a crafted SAMLResponse with an attacker-controlled NameID and a malformed signature to bypass verification processes.

DigitalOcean’s security team was instrumental in identifying these issues following suspicious activity from an unfamiliar network accessing a WordPress admin session. Although the attackers managed to acquire a session cookie, further progress was hindered by network restrictions on the admin panel operations.

Preventive Measures and Recommendations

Security experts emphasize the importance for WordPress site owners to implement the latest updates to mitigate these vulnerabilities. The widespread scanning activity, recorded from multiple IP addresses, suggests non-targeted attempts to exploit any site with the vulnerable plugin, irrespective of its version or edition.

Patchstack has noted that these scanning efforts appear to be opportunistic, with attackers indiscriminately targeting any vulnerable installation. Given the availability of a proof-of-concept code, the urgency for site administrators to apply security patches cannot be overstated. Ensuring these fixes will safeguard against potential exploitation and unauthorized access.

In conclusion, WordPress users utilizing the miniOrange SAML 2.0 plugin should prioritize updating to the latest versions to protect their sites from these critical vulnerabilities and potential administrative breaches.

The Hacker News Tags:admin access, authentication bypass, CVE-2026-15981, CVE-2026-61979, DigitalOcean, miniOrange, Patchstack, SAML vulnerabilities, site security, web security, WordPress

Post navigation

Previous Post: Malware Disguised as GTA 6 Demo Steals User Data
Next Post: Silent Patches Leave Defenders Vulnerable

Related Posts

Critical Node.js Vulnerability Can Cause Server Crashes via async_hooks Stack Overflow Critical Node.js Vulnerability Can Cause Server Crashes via async_hooks Stack Overflow The Hacker News
Amadey and StealC Takedown Recovers 27M Stolen Records Amadey and StealC Takedown Recovers 27M Stolen Records The Hacker News
Chinese Threat Group ‘Jewelbug’ Quietly Infiltrated Russian IT Network for Months Chinese Threat Group ‘Jewelbug’ Quietly Infiltrated Russian IT Network for Months The Hacker News
Cross-Platform QuimaRAT MaaS Targets Multiple OS Cross-Platform QuimaRAT MaaS Targets Multiple OS The Hacker News
Ivanti Warns of Active Exploitation in EPMM Vulnerability Ivanti Warns of Active Exploitation in EPMM Vulnerability The Hacker News
Emerging Cyber Threats and Security Flaws Reviewed Emerging Cyber Threats and Security Flaws Reviewed The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Oracle Server Vulnerability Actively Exploited: CISA Warning
  • Silent Patches Leave Defenders Vulnerable
  • Exploits Targeting miniOrange SAML Vulnerabilities in WordPress
  • Malware Disguised as GTA 6 Demo Steals User Data
  • Critical Command Injection Flaws in TP-Link Routers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Oracle Server Vulnerability Actively Exploited: CISA Warning
  • Silent Patches Leave Defenders Vulnerable
  • Exploits Targeting miniOrange SAML Vulnerabilities in WordPress
  • Malware Disguised as GTA 6 Demo Steals User Data
  • Critical Command Injection Flaws in TP-Link Routers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark