Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

The Hacker News · Aug 25, 2026

Back to News
Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
Security August 25, 2026

Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators. The vulnerabilities, as disclosed by Patchstack, are listed below - CVE-2026-61979 (CVSS score: 8.1) - An unauthenticated privilege escalation

Read original on The Hacker News

Want to stay informed about new business solutions?

Follow us

Ready to build a better digital experience?

We create modern multilingual websites, integrate external services and automate content workflows for growing businesses.