MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-08-24 · via BleepingComputer

WordPress miniOrange plugin flaws exploited for admin account takeover

Two critical authentication bypass vulnerabilities in the miniOrange SAML Single Sign On plugin for WordPress are being actively exploited. Attackers can chain the flaws to forge SAML responses and gain administrator access. The vendor fixed the issues but only disclosed the risk for the free version, leaving paid users unaware.

Expanded Detail

The miniOrange plugin family spans seven products, with the free version alone accounting for 10,000 downloads and roughly 30,000 customers across the paid editions. The flaws let attackers select HMAC-SHA1 as the signature algorithm, causing the plugin to treat the identity provider's public key as a shared secret, while a second bug allowed malformed signatures to pass OpenSSL verification.

Patchstack observed exploitation attempts originating from six IP addresses across Europe, Africa, and the United States. A proof-of-concept for the free edition is publicly available, and because WordPress dashboards do not display update warnings for paid plugin versions, administrators must manually check for patched releases.

Context

Organizations relying on this plugin for single sign-on face a serious exposure window, as many paid-version users were never alerted to the risk. Compromised administrator accounts could allow attackers to modify site content, inject malicious code, or harvest user data. Smaller businesses without dedicated security teams may be especially vulnerable, and the public PoC could accelerate attacks across the WordPress ecosystem.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Anthropic rolls out no-cost OSS Scanner to flag flaws in open-source code · Cybersecurity
This summary is Al-enhanced to contain extended analysis and broader social context. The original is {NAME); the linked article is the authoritative source. Original headline: “Hackers target WordPress sites in miniOrange auth bypass attacks.” Browse more stories.