Critical WordPress SAML SSO Flaws Enable Unauthenticated Admin Account Takeover
ID: 6196e635-f7d3-5008-9f18-adee4a7e45e5
STIX ID: report--6196e635-f7d3-5008-9f18-adee4a7e45e5
Feed Name: Cyber Press
Two critical SAML vulnerabilities in the miniOrange WordPress SSO plugin (CVE-2026-61979 and CVE-2026-15981) allowed attackers to forge SAML assertions and access /wp-admin as any existing account, including administrators. CVE-2026-61979 involved signature-algorithm confusion (treating an RSA public key as an HMAC secret) and CVE-2026-15981 resulted from improper handling of openssl_verify() return values; both scored 9.8 and have been observed in opportunistic scanning. The vendor released fixes for paid Standard editions (17.0.5/17.0.6), but the plugin's multiple independently versioned editions meant many installations could be mistakenly considered patched; administrators are advised to identify their edition, apply the vendor patches, and investigate suspicious administrator sessions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
