Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
Attackers are exploiting two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin, allowing them to sign in as any WordPress user, including administrators. The vulnerabilities, disclosed by Patchstack, are due to signat…
Intelligence analysis by Llama

The miniOrange SAML plugin has two severe vulnerabilities that allow attackers to sign in as any WordPress user, including administrators. The vulnerabilities are due to signature algorithm confusion and accepting malformed signatures as valid. WordPress site owners are advised to apply the latest fixes to stay protected.
Imagine you have a special key that can unlock any door in a house. But, the key is broken, and anyone can use it to unlock any door. That's what's happening with the miniOrange SAML plugin. Attackers can use a broken key to sign in as any WordPress user, including administrators. This can lead to data breaches and other security issues.
Analysis
Vulnerabilities Overview
The miniOrange SAML plugin has two severe vulnerabilities that can allow attackers to sign in as any WordPress user, including administrators. The vulnerabilities are due to signature algorithm confusion and accepting malformed signatures as valid.
CVE-2026-61979
The first vulnerability, CVE-2026-61979, is an unauthenticated privilege escalation vulnerability stemming from signature algorithm confusion. This vulnerability is fixed in version 17.0.5 for the Standard edition.
CVE-2026-15981
The second vulnerability, CVE-2026-15981, is an authentication bypass vulnerability stemming from accepting malformed signatures as valid. This vulnerability is fixed in version 17.0.6 for the Standard edition.
Impact
The vulnerabilities in the miniOrange SAML plugin can allow attackers to gain admin access to WordPress sites, potentially leading to data breaches and other security issues. Site owners are advised to update their plugins to the latest version to stay protected.
Patchstack's Analysis
Patchstack, the WordPress security company, credited the DigitalOcean security team for reporting the issues. The company said an attacker can craft a SAML response with a malformed signature and send it to the plugin, causing it to treat it as valid. The scanning activity has been recorded from several IP addresses, suggesting opportunistic scanning rather than a targeted campaign.
Recommendations
WordPress site owners are advised to apply the latest fixes to stay protected, especially given the availability of a proof-of-concept (PoC) code that allows attackers to chain the flaws to obtain admin privileges and take control of susceptible sites.
Key points
- The miniOrange SAML plugin has two severe vulnerabilities that can allow attackers to sign in as any WordPress user, including administrators.
- The vulnerabilities are due to signature algorithm confusion and accepting malformed signatures as valid.
- WordPress site owners are advised to apply the latest fixes to stay protected.
- The vulnerabilities can lead to data breaches and other security issues if not patched quickly.
If the vulnerabilities in the miniOrange SAML plugin are patched quickly, WordPress site owners can rest assured that their sites are protected from potential attacks. Additionally, the availability of a proof-of-concept (PoC) code that allows attackers to chain the flaws to obtain admin privileges and take control of susceptible sites can serve as a warning to site owners to update their plugins to the latest version.
If the vulnerabilities in the miniOrange SAML plugin are not patched quickly, WordPress site owners may be at risk of data breaches and other security issues. Additionally, the availability of a proof-of-concept (PoC) code that allows attackers to chain the flaws to obtain admin privileges and take control of susceptible sites can make it easier for attackers to exploit the vulnerabilities.



