Hackers Chain Two miniOrange WordPress Plugin Bugs to Log in as Admin
Paid editions of the popular SAML single sign-on plugin were quietly patched in July but never got a public warning, and now attackers are forging login sessions on sites that never updated.

Key points
- Attackers are chaining CVE-2026-61979 and CVE-2026-15981, two authentication bypass flaws in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, to log in as site administrators.
- Fixes shipped in July 2026, but the vendor's public advisory only covered the free edition, leaving six paid versions quietly patched with no alert to customers.
- Security firm Patchstack traced an attack on August 16, when DigitalOcean blocked a suspicious admin session on a site running the Standard edition version 16.1.9.
- Scanning and exploitation are coming from six IP addresses spread across Europe, Africa and the United States, and a working proof-of-concept for the free edition is already public.
- WordPress won't show an update prompt for the paid versions, so site owners must upgrade by hand.
Criminals are breaking into WordPress websites by tricking a popular login plugin into believing they're the site owner.
The plugin is miniOrange SAML 2.0 Single Sign On, made by Xecurify. It lets a WordPress site accept logins from corporate identity services like Microsoft Entra ID or Okta, so staff use their work account instead of a separate WordPress password. That's a useful thing. It's also, right now, a soft target.
How are the hackers getting in?
They're chaining two bugs to forge a valid login. First reported by BleepingComputer, the attacks abuse CVE-2026-61979 and CVE-2026-15981, two flaws in how the plugin checks the digital signature on an incoming login message.
The plain version: when you sign in through a service like Okta, Okta sends the WordPress site a signed message saying "yes, this is really Jane." The plugin is supposed to check that signature against Okta's public key, a piece of cryptographic ID that anyone can see but only Okta can sign with.
The first bug lets the attacker pick which signing method the plugin uses. Choose the wrong one and the plugin treats Okta's public key, which anyone can download, as if it were a shared password. At that point the attacker can sign their own fake message and the plugin waves it through.
The second bug is simpler and, honestly, more embarrassing. When the underlying OpenSSL library returns an error code of -1, meaning "I couldn't verify this," the plugin reads that as success. Malformed signatures get accepted.
If this feels familiar, it should. This is the same family of signature-confusion tricks that have haunted single sign-on implementations since the mid-2010s. Our earlier report on WordPress sites being compromised through hijacked BdThemes plugins shows how often the admin-access angle is the real prize.
Why did paid customers miss the patch?
Nobody told them. Patches went out in July, but Xecurify's public advisory only mentioned the free edition. The six paid editions were fixed in the code, quietly, with no security notice attached. Paying customers assumed there was nothing to do, and the WordPress dashboard didn't contradict them.
Here are the fixed versions to check against:
| Edition | Patched version |
|---|---|
| Free, single site | 5.4.5 |
| Premium, single site | 13.0.4 |
| Standard, single site | 17.06 |
| Premium/Enterprise/All-Inclusive, multisite | 20.2.8 |
| Enterprise/All-Inclusive, single site | 26.0.3 |
| VIP, single site | 32.0.8 |
| VIP, multisite | 35.0.7 |
What does the attack look like in the wild?
On August 16, DigitalOcean blocked a WordPress administrator session that had appeared out of nowhere, from outside the customer's trusted network. Patchstack investigated and found the two bugs chained against the Standard edition, version 16.1.9, to hand the attacker an admin session cookie.
Since then, Patchstack has recorded scanning from six IP addresses across three continents. A working exploit for the free edition is public, which usually means volume goes up, not down.
Should you worry?
Yes, particularly if you're running a paid edition and haven't checked your version. The disclosure gap is the real story here: the vendor patched quietly, left paid customers in the dark, and attackers noticed the window before most site owners did. Watch for new administrator accounts you didn't create.
If your site uses any miniOrange SAML SSO plugin, open the plugin file and check the version number against the table above. Upgrade by hand if you're on a paid edition, then audit your administrator account list and force a session reset for any account that looks unfamiliar.



