Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

The Hacker News by The Hacker News
August 25, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Ravie LakshmananAug 25, 2026Vulnerability / Web Security

Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators.

The vulnerabilities, as disclosed by Patchstack, are listed below –

  • CVE-2026-61979 (CVSS score: 8.1) – An unauthenticated privilege escalation vulnerability stemming from signature algorithm confusion (Fixed in version 17.0.5 for the Standard edition)
  • CVE-2026-15981 (CVSS score: 9.8) – An authentication bypass vulnerability stemming from accepting malformed signatures as valid (Fixed in version 17.0.6 for the Standard edition)

“This is due to the mo_saml_validate_signature() function performing a loose boolean check on the raw tri-state integer returned by PHP’s openssl_verify(), causing an error return value of -1 to be evaluated as truthy and therefore treated as a successful signature verification,” according to a description of CVE-2026-15981 on CVE.org.

“This makes it possible for unauthenticated attackers to log in as any existing WordPress user, including administrators, by submitting a crafted SAMLResponse containing an attacker-controlled NameID and a deliberately malformed signature value that triggers an OpenSSL processing error — bypassing verification entirely and resulting in wp_set_auth_cookie() being called for the targeted account.”

The WordPress security company, which credited the DigitalOcean security team for reporting the issues, said an attacker can craft a SAML response with a malformed signature and send it to the plugin, causing it to treat it as valid.

The cloud infrastructure provider is said to have discovered the vulnerabilities after observing an anomalous WordPress administrator session attempt from outside their trusted network. “The attacker had already used the bypass to obtain a WordPress admin session cookie, but was stalled because the admin panel operations themselves sat restricted behind the trusted network,” Patchstack said.

The scanning activity has been recorded from the following IP addresses –

  • 207.211.214.41
  • 79.127.224.14
  • 102.91.71.83
  • 162.243.116.148
  • 84.201.6.54
  • 64.225.25.188

“The spread suggests opportunistic scanning rather than a targeted campaign,” Patchstack added. “Whoever is running this appears to be throwing the exploit at every site with the plugin installed without checking which edition or version is behind it.”

WordPress site owners are advised to apply the latest fixes to stay protected, especially given the availability of a proof-of-concept (PoC) code that allows attackers to chain the flaws to obtain admin privileges and take control of susceptible sites.



Source link

The Hacker News

The Hacker News

Next Post

Hollyland presenteert nieuwe oplossingen voor professionele liveproductie en contentcreatie op IBC 2026

Recommended.

EU sets out plans to ‘at least’ triple its AI datacentre capacity over the next seven years | Computer Weekly

EU sets out plans to ‘at least’ triple its AI datacentre capacity over the next seven years | Computer Weekly

April 9, 2025
e& réalise un chiffre d’affaires et un bénéfice net record pour l’exercice 2024, augmentant le chiffre d’affaires consolidé de 10,1 % pour atteindre 59,2 milliards d’AED

e& réalise un chiffre d’affaires et un bénéfice net record pour l’exercice 2024, augmentant le chiffre d’affaires consolidé de 10,1 % pour atteindre 59,2 milliards d’AED

February 26, 2025

Trending.

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

May 12, 2026
How ByteDance Made China’s Most Popular AI Chatbot

How ByteDance Made China’s Most Popular AI Chatbot

October 16, 2025
The Coolest Big Data System and Platform Companies Of The 2026 Big Data 100

The Coolest Big Data System and Platform Companies Of The 2026 Big Data 100

June 9, 2026
AWS Vs. Microsoft Vs. Google Cloud Earnings Q2 2026 Face-Off

AWS Vs. Microsoft Vs. Google Cloud Earnings Q2 2026 Face-Off

August 3, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio