Hackers exploit WordPress auth bypass flaws in miniOrange plugin
Hackers are actively exploiting two authentication bypass vulnerabilities in the miniOrange SAML 2.0 plugin for WordPress to seize administrator accounts, Patchstack said on August 16.
Source: BleepingComputer · August 24, 2026 at 10:53 PM · AI-assisted report
Single-source
KUALA LUMPUR, 25 AUGUST 2026 —
Hackers Exploit Critical Flaws in WordPress Plugin, Targeting Malaysian Sites
Market Impact
KUALA LUMPUR, Aug 24 — Hackers are actively exploiting two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, which could allow unauthorized administrative access to websites. The flaws, tracked as CVE-2026-61979 and CVE-2026-15981, enable attackers to forge SAML responses and bypass authentication, posing a significant risk to WordPress-powered sites in Malaysia and globally.
The miniOrange SAML SSO plugin, developed by Xecurify, enables WordPress sites to function as SAML service providers, allowing users to log in via corporate identity platforms such as Microsoft Entra ID, Okta, Google Workspace, or OneLogin. The plugin family includes a free version with 10,000 downloads and six paid editions serving 30,000 customers.
The vulnerabilities were publicly disclosed and patched in July 2026, but the vendor’s advisory only covered the free edition, leaving paid versions without an official alert—despite fixes being available.
Security firm Patchstack reported that attackers have already chained the two flaws to gain administrator access. On August 16, DigitalOcean blocked an anomalous WordPress admin session originating from an untrusted network, later confirming it was linked to the exploitation of the Standard edition plugin (version 16.1.9). Patchstack’s telemetry indicates ongoing exploitation attempts and opportunistic scanning from six IP addresses across Europe, Africa, and the United States.
A proof-of-concept (PoC) exploit for the free edition is publicly available, raising concerns of a surge in attacks.
For Malaysian WordPress site owners, the risk is compounded by the lack of automatic update warnings for paid versions of the plugin. Users must manually upgrade to patched releases (versions 16.2.0 or later) to mitigate the threat. Once attackers gain valid credentials, traditional prevention measures—such as signature-based defenses—become less effective, according to Patchstack’s analysis.
The incident underscores broader cybersecurity challenges in Malaysia’s growing digital economy, where WordPress powers an estimated 40% of all websites. While the immediate threat is linked to the miniOrange plugin, the episode highlights the need for vigilance in third-party integrations and timely patch management.
Cybersecurity agencies in Malaysia, including the National Cyber Security Agency (NACSA), have yet to issue specific advisories, but local IT security firms are urging businesses to audit their WordPress plugins and update vulnerable components.
Looking ahead, the pace of attacks may accelerate as more threat actors adopt the PoC exploit. Website administrators are advised to verify their plugin versions, apply available patches, and monitor for suspicious administrative activity. The episode serves as a reminder of the persistent risks posed by unpatched software, even in widely used platforms.
Related: Microsoft