Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Man Who Told of a Childhood With Wolves Dies at 80

    August 25, 2026

    Scottish National Investment Bank makes ‘painful’ £138m net loss

    August 25, 2026

    Zillow and Redfin settle FTC antitrust case

    August 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Man Who Told of a Childhood With Wolves Dies at 80
    • Scottish National Investment Bank makes ‘painful’ £138m net loss
    • Zillow and Redfin settle FTC antitrust case
    • Hackers target WordPress sites in miniOrange auth bypass attacks
    • Coinbase launches B20 tokenized stocks on Base
    • How a rare bird sparked a wildlife movement across 16 villages in Guyana
    • China’s Rare-Earth Trade Leverage Looms Over Japan, United States
    • How Canada could hit back to hurt the US economy – and Trump
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, August 25
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Hackers target WordPress sites in miniOrange auth bypass attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 25, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators.

    The miniOrange SAML SSO plugin turns a WordPress site into a SAML service provider, letting users log in through corporate identity platforms such as Microsoft Entra ID, Okta, Google Workspace, or OneLogin instead of separate WordPress credentials.

    Created by Xecurify, miniOrange is a family of seven plugins, with a free version that has 10,000 downloads and 30,000 customers for the other six.

    image

    The two vulnerabilities observed in exploitation attempts are tracked as CVE-2026-61979 and CVE-2026-15981 and can be chained together to bypass authentication.

    Because the miniOrange SAML SSO plugin accepts the signature algorithm from incoming SAML responses instead of enforcing the configured one, an attacker can leverage CVE-2026-61979 to select HMAC-SHA1. This causes the plugin to treat the RSA public key from the identity provider (IdP) as the shared secret.

    Since the public key is known, the attacker can forge a signature that the plugin accepts as authentic.

    The second security issue, CVE-2026-15981, causes the plugin to treat an OpenSSL verification error (-1) as a successful result, allowing malformed signatures to pass validation.

    According to security firm Patchstack, the two vulnerabilities were publicly disclosed and fixed in July. However, the vendor’s advisory covered only the free edition, leaving the six paid editions without an alert, even though fixes were provided for those too.

    The following versions addressed the two flaws:

    1. Free, single site – 5.4.5
    2. Premium, single site – 13.0.4
    3. Standard, single site – 17.06
    4. Premium/Enterprise/All-Inclusive, multisite – 20.2.8
    5. Enterprise/All-Inclusive, single site – 26.0.3
    6. VIP, single site – 32.0.8
    7. VIP, multisite – 35.0.7

    Failing to disclose the risk across all versions of the plugin reportedly led many sites running the paid editions to take no action, creating an opportunity for threat actors to exploit the two vulnerabilities.

    Patchstack reports that, on August 16, DigitalOcean blocked an anomalous WordPress administrator session originating outside its trusted network.

    The investigation showed that attackers have chained the two flaws to obtain an admin session cookie through the Standard edition plugin in version 16.1.9.

    Patchstack’s data shows that exploitation attempts and opportunistic scanning are underway, launched from six IP addresses across Europe, Africa, and the United States.

    A proof-of-concept (PoC) exploit targeting the free edition is also publicly available, so the pace of attacks could increase at any time.

    Patchstack warns that the WordPress administrator dashboard will not show update warnings for the paid versions of the plugin, so website owners must manually upgrade to a patched release.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    attacks auth Bypass hackers miniOrange sites Target WordPress
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

    Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning

    The Outsized Shadow: Why 5% of AI Users Are Your Biggest Security Risk

    Circle Gets $140 Target as Bernstein Eyes USDC Growth Cycle

    ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited

    Target removed kid’s Halloween costume from website amid backlash over blackface, minstrel imagery

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Man Who Told of a Childhood With Wolves Dies at 80

    August 25, 2026

    Scottish National Investment Bank makes ‘painful’ £138m net loss

    August 25, 2026

    Zillow and Redfin settle FTC antitrust case

    August 25, 2026

    Hackers target WordPress sites in miniOrange auth bypass attacks

    August 25, 2026
    Latest Posts

    The Doctor and His Diary: What Fauci’s Innermost Musings Reveal

    July 29, 2026

    Iran Considered Retaliatory Strike on Ukrainian Seaport

    July 29, 2026

    The French presidential candidate who wants to blow up the Franco-German engine – POLITICO

    July 29, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Man Who Told of a Childhood With Wolves Dies at 80

    August 25, 2026

    Scottish National Investment Bank makes ‘painful’ £138m net loss

    August 25, 2026

    Zillow and Redfin settle FTC antitrust case

    August 25, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.