TWO critical authentication bypass vulnerabilities (CVEs 2026-61979 and 2026-15981) in the miniOrange SAML 2.0 Single Sign-On WordPress plugin are currently being exploited. Both vulnerabilities allow unauthenticated attackers to access WordPress admin areas as any user, including administrators.
The first vulnerability involves an algorithm confusion flaw where the plugin mistakenly trusts the SAML response's signature algorithm, while the second involves mishandling OpenSSL verification results due to a coding error. These vulnerabilities were not listed in any database for paid editions, misleading administrators into thinking they were secure. DigitalOcean discovered the vulnerabilities after observing anomalous admin login attempts.
As many as seven separate editions of the plugin exist, complicating the tracking and vulnerability management across them. The article emphasizes the need for manual updates and monitoring of affected installations.