TRENDING
Rows of identical brass-colored apartment mailboxes with small locks and name labels along an orange corridor wall
October 9, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
Street-level upward view of the Monetary Authority of Singapore building and neighbouring office towers under a pale sky
October 9, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
Cast-iron late Qing dynasty coin minting press with a large flywheel, displayed in a museum case
October 9, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google
Rows of closed oak library card catalog drawers, each with a brass pull and a blank label holder
October 9, 2026
How to Encrypt PII in Python and Keep It Searchable With Blind Indexes
Close-up of a vintage Western Electric manual telephone switchboard with orange lamps, red patch cords plugged into jacks, a rotary dial and a black handset
October 9, 2026
Microsoft’s Agent Lightning v1.0 Turns Agent Training Into a Sample-Accounting Problem
09 Oct 2026
SXZ.io SXZ.io
  • Home
Search the Site
Popular Searches:
Technology Amazon AI
Recent Posts
Two orange safety relief valves on grey pressure vessels in an industrial plant
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
Yellow diamond-shaped merging traffic warning sign showing a side road joining a main road
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A lugworm lying on wet sand and mud at low tide
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
SXZ.io SXZ.io
  • Home

Categories

Articles 232 Posts
News 234 Posts
Learning Hub 204 Posts
Home/News/A Critical WordPress SSO Login Bypass Stayed Hidden in Six Untracked Plugin Editions
News

A Critical WordPress SSO Login Bypass Stayed Hidden in Six Untracked Plugin Editions

Two critical authentication bypass bugs in a WordPress SAML plugin were silently patched across six paid editions, leaving every vulnerability scanner blind until DigitalOcean caught the bug being...

August 21, 2026 5 Min Read
38

A critical authentication bypass in a WordPress single sign-on plugin was patched in six of its seven paid editions with no public disclosure at all, invisible to every vulnerability scanner that tracks the software, until DigitalOcean’s security team caught an attacker actively exploiting it on its own infrastructure. The plugin, miniOrange’s SAML Single Sign On, lets WordPress sites authenticate through SAML 2.0 identity providers such as Okta, Azure AD, and Google Workspace. Patchstack published the full findings on August 21, crediting DigitalOcean with the discovery, the root cause analysis, and fixes for editions the vendor had already patched quietly.

Table Of Content

  • A Bypass DigitalOcean Almost Missed
  • Two Ways to Log In as Anyone
  • Seven Editions, One Listing
  • No Update Prompt, No Warning
  • What to Do If You Run This Plugin

A Bypass DigitalOcean Almost Missed

On August 16, DigitalOcean’s defense-in-depth controls flagged an anomalous WordPress administrator session attempt originating from outside the company’s trusted network. According to Patchstack, the attacker had already used the bypass to obtain a valid admin session cookie, but the intrusion stalled because admin panel operations were separately restricted to DigitalOcean’s trusted network, a second control the attacker had not defeated. DigitalOcean’s team reproduced the bypass the next day against its own installation of the plugin, the Standard edition, version 16.1.9, and began tracing the bug to its root cause.

Two Ways to Log In as Anyone

The reproduction confirmed two separate authentication bypasses, each already logged in the National Vulnerability Database for the plugin’s free edition. CVE-2026-15981, rated 9.8 out of 10 (critical) with a low attack complexity, stems from how the plugin checks a SAML response’s digital signature. PHP’s openssl_verify() function is tri-state: it returns 1 for a valid signature, 0 for an invalid one, and -1 when OpenSSL itself throws an internal error. The plugin treated that result as a plain boolean, and in PHP, -1 evaluates as true. A malformed signature that tripped OpenSSL’s error path was accepted as a genuine one, letting an attacker submit a forged SAML response and log in as any existing user, including an administrator, without a password.

CVE-2026-61979, rated 8.1 (high severity) with a higher attack complexity, is a separate signature algorithm confusion bug. The plugin lets an incoming SAML response name its own signature algorithm. By setting that field to HMAC-SHA1, an attacker can trick the plugin into treating the identity provider’s public RSA key, which is public by definition, as a shared HMAC secret, then sign a forged assertion with a key the plugin already trusts. Patchstack traced both flaws to specific lines in the plugin’s bundled SAML2Core library and its own Utilities.php file.

Seven Editions, One Listing

Both CVEs were originally disclosed for the plugin’s free edition, distributed under the WordPress.org listing miniorange-saml-20-single-sign-on, which shows 10,000+ active installs. What DigitalOcean found is that miniOrange also sells six paid editions, Premium, Standard, a multisite Premium/Enterprise/All-Inclusive tier, a single-site Enterprise/All-Inclusive tier, and VIP editions for both single-site and multisite installs, all distributed under that same WordPress.org slug but versioned completely independently of the free tier and of each other. Free runs 3.x through 5.x. Premium runs 11.x through 13.x. Standard, the edition DigitalOcean was running, spans 15.x through 17.x. A version number alone does not indicate which edition a site is running.

That independence broke every vulnerability database’s coverage at once. Public advisories fixed the free edition at version 5.4.5. A scanner using that number as its cutoff sees a Standard-edition site on version 16.1.9, or a VIP site on 32.0.7, as already patched, since those version numbers are higher than 5.4.5, even though every one of those editions was still running the vulnerable code. miniOrange had patched all six paid editions quietly, according to Patchstack, with no changelog entry and no public advisory for any of them.

No Update Prompt, No Warning

The consequences reached beyond vulnerability scanners into the WordPress dashboard itself. A site running the vulnerable Standard edition 16.1.9 shows no pending update in its admin panel, even though the patched 17.0.6 has been available on the same product line the whole time, because WordPress’s update mechanism does not prompt across an edition’s separate version line. Patchstack says the only way to move from a vulnerable 16.x release to the patched 17.x release is a manual plugin file upload.

Patchstack also found evidence of opportunistic scanning rather than a single targeted campaign: it lists exploitation attempts against miniOrange SSO endpoints from IP addresses geolocated to Belgium, Nigeria, the United States, and Germany, a spread the firm says points to attackers testing the exploit against any site running the plugin, regardless of which edition or version answers back.

What to Do If You Run This Plugin

Patchstack’s advisory includes a table mapping each of the seven editions to its vulnerable version range and its patched version, and it recommends checking that table directly rather than trusting a dashboard update prompt or a scanner’s clean report. Site owners who cannot update immediately can apply two narrowly scoped code changes Patchstack published as temporary hotfixes: one rejects any SAML response that requests the HMAC-SHA1 algorithm, and the other requires openssl_verify() to return exactly 1 rather than any truthy value. Patchstack describes both as meant to buy time, not to replace the vendor’s own fix. The firm also recommends checking server logs for administrator sessions originating from unexpected IP ranges, the same signal that first surfaced the bug at DigitalOcean.

The timeline moved quickly once DigitalOcean flagged the issue. DigitalOcean reported the bypass and its edition-versioning discovery to Patchstack on August 17, the same day a bug bounty report against a separate installation of the same paid edition confirmed wider outside interest in the bug. miniOrange supplied the complete edition and version matrix on August 18, and Patchstack updated its vulnerability database with all seven ranges that day, three days before publishing the full writeup.

Patchstack frames the incident as a structural problem rather than a one-off vendor mistake. A vulnerability record normally assumes one WordPress.org slug maps to one climbing version number, an assumption that fails the moment a vendor ships several independently numbered products under a single listing without disclosing all of them. As the firm put it in its writeup: “When a vendor runs seven independently numbered editions under one slug and patches six of them without a public advisory, the entire ecosystem downstream of them goes blind at once: databases, scanners, dashboards, and the site admins relying on all three.”

Tags:

Authentication BypassDigitalOceanSAMLVulnerability DisclosureWordPress Security

Share

Dew drops outlining the threads and junctions of a spider web against a dark background, a natural example of nodes connected by relationships
Previous Post

How to Build a Dependency Graph With Neo4j and Python to Trace Vulnerable Packages

A conductor lit by a spotlight beam directs an orchestra on a dark stage, a visual metaphor for coordinating many automated systems from one governed point of control.
Next Post

Red Hat’s Automation Orchestrator Turns AI Agent Recommendations Into a Governed Workflow

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest
08 Oct
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
08 Oct
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
Trending
October 8, 2026
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
October 8, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
October 8, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google

Related Posts

Rows of server racks in a data center representing network infrastructure targeted by botnets
News

C0XMO Botnet Shows Why Old Router Firmware Still Matters

June 7, 2026
Close-up of a USB flash drive, representing physical data-theft risk in office security incidents
News

Fake IT Support Is Now Walking Through the Front Door

June 7, 2026
A phone security app on a smartphone resting on a laptop keyboard.
News

Everest Forms Pro Flaw Is Being Exploited to Create Rogue WordPress Admins

June 7, 2026
A phone secured by a padlock, illustrating AI data-leak containment and security controls.
News

OpenAI’s Lockdown Mode Is a Data-Leak Brake, Not a Prompt-Injection Cure

June 8, 2026
SXZ.io SXZ.io
  • [email protected]

Categories

Articles
Learning Hub
News

All Rights Reserved by SXZ.io ©2026