Attackers Target WordPress SAML Plugin Flaws That Could Grant Admin Access

Cybersecurity researchers have warned that attackers are actively scanning for two serious vulnerabilities affecting the miniOrange SAML 2.0 Single Sign On plugin for WordPress.
The flaws could allow an attacker to bypass the normal login process and gain access to a WordPress site as another user, including an administrator.
The most serious issue, tracked as CVE-2026-15981, has a severity score of 9.8 out of 10. It is caused by a problem in how the plugin checks digital signatures used to verify SAML login requests.
Under certain conditions, the plugin can mistakenly treat an invalid or malformed signature as valid. An attacker could exploit this by sending a specially crafted SAML response containing the username or identity of an existing WordPress user. This could allow them to log in without knowing the user’s password.
A second vulnerability, CVE-2026-61979, could also lead to privilege escalation and has a severity score of 8.1.
Security researchers said the vulnerabilities were discovered after suspicious activity involving a WordPress administrator account was detected. In that case, an attacker reportedly managed to obtain an administrator session cookie but was unable to perform further actions because access to the admin panel was restricted to a trusted network.
Researchers have since detected scanning activity from multiple IP addresses, suggesting attackers may be searching widely for vulnerable WordPress websites rather than targeting specific organizations.
The issues have been fixed in newer versions of the miniOrange SAML plugin. Website owners using the affected Standard edition are advised to update to version 17.0.6 or later as soon as possible.
With proof-of-concept code already available, delaying updates could leave vulnerable WordPress sites exposed to attackers who may be able to gain administrator-level control.






