Skip to content
Breaking
UK PM Andy Burnham firm in support of Ukraine, unafraid of Russian threatStone inscription with Prophet's name found at ancient Ani site in TurkeyUS judge delays Lockerbie bombing trial over new evidenceHongkong Post wins HK$4.6 billion bailout after eight straight years of lossesPhilippines retains Moody’s Baa2 rating with stable outlookEl Niño preparedness may tame food-price surge, BSP saysCanadian businesses lag in AI adoption despite personal use by executivesMalaysia’s school bullying cases rise 142% in two years amid calls for tougher enforcementMforce extends electric motorcycle rebate deadline to Oct 31, 2026Critical unpatched flaw in Calix routers exposes home networks to internetHonor Pad 20 series launches in Malaysia with RM1,999 starting priceHackers exploit WordPress auth bypass flaws in miniOrange pluginAI-powered attacks target Siemens PLCs used in MalaysiaWordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows PasswordsEuropean stocks flat as markets weigh Iran tensions, await economic dataS&P 500, Nasdaq end down on tech stocks, investors weigh Iran movesRCEP’s investment test: four years in, the bloc still struggles to anchor Asian capitalTrump bought SpaceX shares two weeks after blockbuster IPOZillow agrees to pay Redfin US$100 million to settle FTC antitrust caseUS expands sanctions on Iran’s oil trade and financial networksUK PM Andy Burnham firm in support of Ukraine, unafraid of Russian threatStone inscription with Prophet's name found at ancient Ani site in TurkeyUS judge delays Lockerbie bombing trial over new evidenceHongkong Post wins HK$4.6 billion bailout after eight straight years of lossesPhilippines retains Moody’s Baa2 rating with stable outlookEl Niño preparedness may tame food-price surge, BSP saysCanadian businesses lag in AI adoption despite personal use by executivesMalaysia’s school bullying cases rise 142% in two years amid calls for tougher enforcementMforce extends electric motorcycle rebate deadline to Oct 31, 2026Critical unpatched flaw in Calix routers exposes home networks to internetHonor Pad 20 series launches in Malaysia with RM1,999 starting priceHackers exploit WordPress auth bypass flaws in miniOrange pluginAI-powered attacks target Siemens PLCs used in MalaysiaWordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows PasswordsEuropean stocks flat as markets weigh Iran tensions, await economic dataS&P 500, Nasdaq end down on tech stocks, investors weigh Iran movesRCEP’s investment test: four years in, the bloc still struggles to anchor Asian capitalTrump bought SpaceX shares two weeks after blockbuster IPOZillow agrees to pay Redfin US$100 million to settle FTC antitrust caseUS expands sanctions on Iran’s oil trade and financial networks
AI Edge

Hackers exploit WordPress auth bypass flaws in miniOrange plugin

Hackers are actively exploiting two authentication bypass vulnerabilities in the miniOrange SAML 2.0 plugin for WordPress to seize administrator accounts, Patchstack said on August 16.

Source: BleepingComputer · August 24, 2026 at 10:53 PM · AI-assisted report

Single-source
Hackers exploit WordPress auth bypass flaws in miniOrange plugin
Photo: wocintechchat.com via woc_tech (BY)

KUALA LUMPUR, 25 AUGUST 2026 —

Listen to this article

DomainFork Audio · read aloud

Share

Hackers Exploit Critical Flaws in WordPress Plugin, Targeting Malaysian Sites

Market Impact

KUALA LUMPUR, Aug 24 — Hackers are actively exploiting two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, which could allow unauthorized administrative access to websites. The flaws, tracked as CVE-2026-61979 and CVE-2026-15981, enable attackers to forge SAML responses and bypass authentication, posing a significant risk to WordPress-powered sites in Malaysia and globally.

The miniOrange SAML SSO plugin, developed by Xecurify, enables WordPress sites to function as SAML service providers, allowing users to log in via corporate identity platforms such as Microsoft Entra ID, Okta, Google Workspace, or OneLogin. The plugin family includes a free version with 10,000 downloads and six paid editions serving 30,000 customers.

The vulnerabilities were publicly disclosed and patched in July 2026, but the vendor’s advisory only covered the free edition, leaving paid versions without an official alert—despite fixes being available.

Security firm Patchstack reported that attackers have already chained the two flaws to gain administrator access. On August 16, DigitalOcean blocked an anomalous WordPress admin session originating from an untrusted network, later confirming it was linked to the exploitation of the Standard edition plugin (version 16.1.9). Patchstack’s telemetry indicates ongoing exploitation attempts and opportunistic scanning from six IP addresses across Europe, Africa, and the United States.

A proof-of-concept (PoC) exploit for the free edition is publicly available, raising concerns of a surge in attacks.

For Malaysian WordPress site owners, the risk is compounded by the lack of automatic update warnings for paid versions of the plugin. Users must manually upgrade to patched releases (versions 16.2.0 or later) to mitigate the threat. Once attackers gain valid credentials, traditional prevention measures—such as signature-based defenses—become less effective, according to Patchstack’s analysis.

The incident underscores broader cybersecurity challenges in Malaysia’s growing digital economy, where WordPress powers an estimated 40% of all websites. While the immediate threat is linked to the miniOrange plugin, the episode highlights the need for vigilance in third-party integrations and timely patch management.

Cybersecurity agencies in Malaysia, including the National Cyber Security Agency (NACSA), have yet to issue specific advisories, but local IT security firms are urging businesses to audit their WordPress plugins and update vulnerable components.

Looking ahead, the pace of attacks may accelerate as more threat actors adopt the PoC exploit. Website administrators are advised to verify their plugin versions, apply available patches, and monitor for suspicious administrative activity. The episode serves as a reminder of the persistent risks posed by unpatched software, even in widely used platforms.

Related: Microsoft

Reporting based on BleepingComputer. Figures and claims are subject to revision as the story develops. DomainFork publishes editorial context, not investment advice — see our editorial standards.