Attackers are hitting WordPress sites through miniOrange SAML bypasses
Patchstack tracked CVE-2026-61979 and CVE-2026-15981 in miniOrange SAML 2.0 SSO. Fixes shipped in July, but the advisory covered only the free edition.

On August 24 BleepingComputer reported Patchstack’s findings on two authentication bypasses in the miniOrange SAML 2.0 SSO WordPress plugin: CVE-2026-61979 and CVE-2026-15981. Fixes arrived in July, but the public advisory covered only the free edition.
What we know
- Patchstack assigned CVE-2026-61979 and CVE-2026-15981 to miniOrange SAML 2.0 SSO.
- Fixes shipped in July, but the advisory covered only the free edition.
- CVE-2026-61979 forces HMAC-SHA1 and treats the identity provider’s RSA public key as a shared secret.
- CVE-2026-15981 treats OpenSSL verify error -1 as success.
- DigitalOcean blocked an anomalous administrator on August 16 on Standard 16.1.9.
Takeaways
- A July fix did not mean a complete public advisory for paid editions.
- Both bugs fail closed verification: one misuses the IdP key, the other ignores an OpenSSL error.
- At least one host saw live abuse on August 16.
Source: BleepingComputer


