{"id":2516,"date":"2026-08-25T09:59:55","date_gmt":"2026-08-25T09:59:55","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2516"},"modified":"2026-08-25T09:59:55","modified_gmt":"2026-08-25T09:59:55","slug":"attackers-target-miniorange-saml-flaws-that-can-grant-wordpress-admin-access","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2516","title":{"rendered":"Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Aug 25, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Web Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhtxn6tX1r1BmVfN_4cdoh6p5jmcAe3D9ckNhjscacXx5HpxZJAdb1SvIWo404cGlwahzCLyFIRB-MdUjGcQdBLLC5pMwaCB75e9AT5jKvC49cvIP5jGIOB4IjcQGaOpibWbIPKj929DICeMilGRZn5JmVIcVslRm2hWgz5RTXIZK5d2b2N5dlEnRBBwWVO\/s1700-e365\/wordpress-hack.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators.<\/p>\n<p>The vulnerabilities, as disclosed by <a href=\"https:\/\/patchstack.com\/articles\/one-slug-seven-editions-the-miniorange-saml-sso-bug-that-let-anyone-log-in-as-your-wordpress-admin\/\" target=\"_blank\">Patchstack<\/a>, are listed below &#8211;<\/p>\n<ul>\n<li><strong><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-61979\" target=\"_blank\">CVE-2026-61979<\/a><\/strong> (CVSS score: 8.1) &#8211; An unauthenticated privilege escalation vulnerability stemming from signature algorithm confusion (Fixed in version 17.0.5 for the Standard edition)<\/li>\n<li><strong><a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-15981\" target=\"_blank\">CVE-2026-15981<\/a><\/strong> (CVSS score: 9.8) &#8211; An authentication bypass vulnerability stemming from accepting malformed signatures as valid (Fixed in version 17.0.6 for the Standard edition)<\/li>\n<\/ul>\n<p>\u00abThis is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP&#8217;s openssl_verify(), causing an error return value of -1 to be evaluated as truthy and therefore treated as a successful signature verification,\u00bb according to a description of CVE-2026-15981 on CVE.org.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/zero-trust-claude-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj8iAp2j8rqTq6aptj6yiYHC-B73UxnWI2NQMt0azp6OVLq9JkO8cpYokLWa8t_IKqrHKPsaM5D_lQ9Ip7kZTi3at4oYfzN1m1b_T4b6MuzBWtmlhdLcQ0nZHicD94rliREFDRewsKBQCTYrAAVNzYKj84_0EZskDUxvkc972s9fYAqcQGEQjVZTc0cr7TB\/s728-e100\/ThreatLocker-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abThis makes it possible for unauthenticated attackers to log in as any existing WordPress user, including administrators, by submitting a crafted SAMLResponse containing an attacker-controlled NameID and a deliberately malformed signature value that triggers an OpenSSL processing error \u2014 bypassing verification entirely and resulting in wp_set_auth_cookie() being called for the targeted account.\u00bb<\/p>\n<p>The WordPress security company, which credited the DigitalOcean security team for reporting the issues, said an attacker can craft a SAML response with a malformed signature and send it to the plugin, causing it to treat it as valid.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjYevjba6N2QNYvYUMyVCK8kIJsA5m29GPpGU2SoUuxg_Meo2sDATxtZ_WSTC62JNH80yalaHPHCEI0DAlshWNOiL82nqt17TnANm7962KpUGKAlUca4B1fpyM1oflpzZrD-ZokejMhy3syCDamrnyie_I0Gfgcv0oE1aZJTxj3Km4yD-1Hwf5vEkeYLfi1\/s1700-e365\/word.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjYevjba6N2QNYvYUMyVCK8kIJsA5m29GPpGU2SoUuxg_Meo2sDATxtZ_WSTC62JNH80yalaHPHCEI0DAlshWNOiL82nqt17TnANm7962KpUGKAlUca4B1fpyM1oflpzZrD-ZokejMhy3syCDamrnyie_I0Gfgcv0oE1aZJTxj3Km4yD-1Hwf5vEkeYLfi1\/s1700-e365\/word.jpg\" alt=\"\" border=\"0\" data-original-height=\"476\" data-original-width=\"754\"\/><\/a><\/div>\n<p>The cloud infrastructure provider is said to have discovered the vulnerabilities after observing an anomalous WordPress administrator session attempt from outside their trusted network. \u00abThe attacker had already used the bypass to obtain a WordPress admin session cookie, but was stalled because the admin panel operations themselves sat restricted behind the trusted network,\u00bb Patchstack said.<\/p>\n<p>The scanning activity has been recorded from the following IP addresses &#8211;<\/p>\n<ul>\n<li>207.211.214.41<\/li>\n<li>79.127.224.14<\/li>\n<li>102.91.71.83<\/li>\n<li>162.243.116.148<\/li>\n<li>84.201.6.54<\/li>\n<li>64.225.25.188<\/li>\n<\/ul>\n<p>\u00abThe spread suggests opportunistic scanning rather than a targeted campaign,\u00bb Patchstack added. \u00abWhoever is running this appears to be throwing the exploit at every site with the plugin installed without checking which edition or version is behind it.\u00bb<\/p>\n<p>WordPress site owners are advised to apply the latest fixes to stay protected, especially given the availability of a proof-of-concept (PoC) code that allows attackers to chain the flaws to obtain admin privileges and take control of susceptible sites.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Aug 25, 2026Vulnerability \/ Web Security Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2517,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[130,129,622,11,2437,3146,3147,492,1927],"class_list":["post-2516","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-access","tag-admin","tag-attackers","tag-flaws","tag-grant","tag-miniorange","tag-saml","tag-target","tag-wordpress"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2516","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2516"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2516\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2517"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2516"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2516"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2516"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}