August 25, 2026
wordpress-hack.jpg

I show You how To Make Huge Profits In A Short Time With Cryptos!

Ravie LakshmananAug 25, 2026Vulnerability / Internet Safety

Unhealthy actors are trying to use two extreme unauthenticated authentication bypasses within the Xecurify miniOrange SAML 2.0 Single Signal On plugin that make it potential for an attacker to sign up as any WordPress consumer, together with directors.

The vulnerabilities, as disclosed by Patchstack, are listed beneath –

  • CVE-2026-61979 (CVSS rating: 8.1) – An unauthenticated privilege escalation vulnerability stemming from signature algorithm confusion (Fastened in model 17.0.5 for the Normal version)
  • CVE-2026-15981 (CVSS rating: 9.8) – An authentication bypass vulnerability stemming from accepting malformed signatures as legitimate (Fastened in model 17.0.6 for the Normal version)

“That is as a result of mo_saml_validate_signature() operate performing a unfastened boolean verify on the uncooked tri-state integer returned by PHP’s openssl_verify(), inflicting an error return worth of -1 to be evaluated as truthy and subsequently handled as a profitable signature verification,” based on an outline of CVE-2026-15981 on CVE.org.

“This makes it potential for unauthenticated attackers to log in as any current WordPress consumer, together with directors, by submitting a crafted SAMLResponse containing an attacker-controlled NameID and a intentionally malformed signature worth that triggers an OpenSSL processing error — bypassing verification solely and leading to wp_set_auth_cookie() being referred to as for the focused account.”

The WordPress safety firm, which credited the DigitalOcean safety workforce for reporting the problems, stated an attacker can craft a SAML response with a malformed signature and ship it to the plugin, inflicting it to deal with it as legitimate.

The cloud infrastructure supplier is alleged to have found the vulnerabilities after observing an anomalous WordPress administrator session try from outdoors their trusted community. “The attacker had already used the bypass to acquire a WordPress admin session cookie, however was stalled as a result of the admin panel operations themselves sat restricted behind the trusted community,” Patchstack stated.

The scanning exercise has been recorded from the next IP addresses –

  • 207.211.214.41
  • 79.127.224.14
  • 102.91.71.83
  • 162.243.116.148
  • 84.201.6.54
  • 64.225.25.188

“The unfold suggests opportunistic scanning quite than a focused marketing campaign,” Patchstack added. “Whoever is operating this seems to be throwing the exploit at each website with the plugin put in with out checking which version or model is behind it.”

WordPress website homeowners are suggested to use the most recent fixes to remain protected, particularly given the supply of a proof-of-concept (PoC) code that permits attackers to chain the failings to acquire admin privileges and take management of vulnerable websites.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *