Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities

CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin.

WordPress vulnerability exploited

Threat actors have been attempting to hack WordPress websites by exploiting two recently patched vulnerabilities affecting a MiniOrange plugin.

The two vulnerabilities are CVE-2026-61979 and CVE-2026-15981, and they affect the MiniOrange SAML 2.0 Single Sign-On (SSO) plugin, which enables SSO for WordPress websites. 

The free edition of the plugin is installed on more than 10,000 WordPress sites, but there are also several paid and enterprise versions for which usage statistics are not available. 

According to an analysis conducted by DigitalOcean and security firm Patchstack, the vulnerabilities are critical authentication bypasses that can be exploited to log in as any WordPress user, including administrators. 

Threat actors have been attempting to exploit CVE-2026-61979 and CVE-2026-15981 in what Patchstack described as opportunistic attacks rather than a targeted campaign. 

The problem is that while all affected versions of the MiniOrange SAML 2.0 SSO plugin have been patched, the developer has not warned users about the potential risks. Only the free edition has an advisory that mentions the fix in version 5.4.5, but it’s listed as a bugfix rather than a security patch. 

Advertisement. Scroll to continue reading.

In the case of the paid editions, users have not been notified and a different versioning system makes it difficult to tell whether a website is patched; users have to manually update the plugin.

“Whoever is running this appears to be throwing the exploit at every site with the plugin installed without checking which edition or version is behind it,” Patchstack warned. “This is exactly the behavior that makes the silent-patch situation dangerous. The attacker does not need to know which edition you run, you do.”

SecurityWeek has reached out to the developer for comment and will update this article if it responds.

Related: 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw

Related: WordPress 7.0.4 Patches Remote Code Execution Vulnerability

Related: WP2Shell WordPress Vulnerabilities Exploited in the Wild

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice.

Register

Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction.

Register

People on the Move

Rapid7 has named Rik Ferguson as VP of Security Intelligence.

Cytactic has appointed Tim Brown as CSO.

Scott Simkin has joined Vega as CMO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.