Hackers target WordPress sites in miniOrange auth bypass attacks
Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. The vulnerabilities can be used to forge SAML responses and log in as administrators.
Intelligence analysis by Llama

Hackers are targeting WordPress sites using a vulnerability in the miniOrange SAML 2.0 Single Sign On plugin. The vulnerability allows attackers to forge SAML responses and log in as administrators. The issue has been publicly disclosed and fixed in July, but the vendor's advisory only covered the free edition, leaving the paid editions without an alert.
Imagine you have a special key that lets you into a secret club. But someone finds out how to make a fake key that looks just like the real one. They can use this fake key to get into the club without being caught. This is what's happening with the miniOrange SAML 2.0 Single Sign On plugin. Hackers are making fake keys that let them get into WordPress sites without being detected.
Analysis
Vulnerability Overview
The miniOrange SAML 2.0 Single Sign On plugin is a popular tool for WordPress sites, allowing users to log in through corporate identity platforms such as Microsoft Entra ID, Okta, Google Workspace, or OneLogin. However, a vulnerability in the plugin has been discovered, which can be used to forge SAML responses and log in as administrators. The vulnerability is tracked as CVE-2026-61979 and CVE-2026-15981 and can be chained together to bypass authentication.
Exploitation Attempts
Patchstack reports that attackers have chained the two flaws to obtain an admin session cookie through the Standard edition plugin in version 16.1.9. The investigation showed that attackers have launched exploitation attempts and opportunistic scanning from six IP addresses across Europe, Africa, and the United States. A proof-of-concept (PoC) exploit targeting the free edition is also publicly available, so the pace of attacks could increase at any time.
Prevention and Mitigation
Patchstack warns that the WordPress administrator dashboard will not show update warnings for the paid versions of the plugin, so website owners must manually upgrade to a patched release. Once attackers have valid credentials, only 37% of their actions are blocked. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
Key points
- Hackers are targeting WordPress sites using a vulnerability in the miniOrange SAML 2.0 Single Sign On plugin.
- The vulnerability allows attackers to forge SAML responses and log in as administrators.
- The issue has been publicly disclosed and fixed in July, but the vendor's advisory only covered the free edition, leaving the paid editions without an alert.
- Website owners must manually upgrade to a patched release of the plugin to prevent exploitation.
- Once attackers have valid credentials, only 37% of their actions are blocked.
If website owners upgrade to a patched release of the miniOrange SAML 2.0 Single Sign On plugin, they can prevent hackers from exploiting the vulnerability. This will help keep their WordPress sites secure and prevent unauthorized access.
If website owners do not upgrade to a patched release of the miniOrange SAML 2.0 Single Sign On plugin, hackers may be able to exploit the vulnerability and gain unauthorized access to their WordPress sites. This could have serious consequences, including data breaches and financial losses.



