HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Critical Authentication‑Bypass Vulnerabilities (CVE‑2026‑61979 & CVE‑2026‑15981) in miniOrange SAML SSO Plugin for WordPress

Researchers disclosed two auth‑bypass flaws in the miniOrange SAML SSO WordPress plugin that let attackers forge SAML responses and gain admin sessions. The issue highlights the need for robust SOC 2 access‑control evidence and comprehensive patch management.

LiveThreat™ Intelligence · 📅 August 25, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
5 recommended
📰
Source
bleepingcomputer.com

Critical Authentication‑Bypass Vulnerabilities (CVE‑2026‑61979 & CVE‑2026‑15981) in miniOrange SAML SSO Plugin for WordPress

What Happened — Researchers identified two critical auth‑bypass flaws in the miniOrange SAML 2.0 Single Sign‑On plugin for WordPress (CVE‑2026‑61979, CVE‑2026‑15981). The bugs allow an attacker to forge SAML responses and obtain an administrator session cookie, effectively logging in as a site admin. Exploitation attempts have been observed in the wild against both free and paid editions.

Why It Matters for Compliance & Audit Readiness

  • The scenario directly tests the effectiveness of SOC 2 Access Control criteria (CC6.1‑CC6.6) – unauthorized access to privileged accounts must be prevented, detected, and logged.
  • Continuous‑compliance programs need verifiable evidence that SAML‑based SSO configurations enforce a single, approved signature algorithm and that patch management covers all product tiers.
  • A breach of admin credentials would invalidate the “least‑privilege” and “monitoring” controls auditors expect, creating gaps in your audit evidence.

Who Is Affected — Any organization that runs WordPress sites with the miniOrange SAML SSO plugin, spanning SaaS providers, e‑commerce platforms, media sites, and internal corporate portals.

Recommended Actions

  • Immediately upgrade every miniOrange SAML SSO installation to the patched versions listed in the vendor advisory (free 5.4.5, premium 13.0.4, etc.).
  • Enforce a fixed, approved signature algorithm in the SAML configuration; do not accept the algorithm supplied by the IdP.
  • Conduct a rapid inventory of all WordPress instances, verify patch status across all paid editions, and document the remediation as audit evidence.
  • Review and tighten admin session monitoring (e.g., IP‑allow‑lists, MFA, anomalous‑session alerts).
  • Capture the patch‑verification logs and SAML‑policy settings in your continuous‑compliance repository for SOC 2 audit readiness.

Source: BleepingComputer – Hackers target WordPress sites in miniOrange auth bypass attacks

Technical Notes

  • CVE‑2026‑61979 – Allows selection of HMAC‑SHA1 as the signature algorithm, causing the plugin to treat the IdP’s RSA public key as a shared secret.
  • CVE‑2026‑15981 – Treats an OpenSSL verification error (‑1) as a successful validation, letting malformed signatures pass.
  • Both flaws can be chained to forge a valid SAML response and obtain an admin session cookie.
  • Exploitation attempts have originated from six IP addresses across Europe, Africa, and the United States; a PoC for the free edition is publicly available.
📰 Original Source
https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-in-miniorange-auth-bypass-attacks/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →