< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-08-25T14:04:07+05:30

Exploitation of SAML Vulnerabilities in miniOrange Plugin Enables WordPress Admin Access

Attackers are exploiting two critical SAML vulnerabilities in the miniOrange plugin, allowing unauthorized access to WordPress admin accounts. The flaws, rated 8.1 and 9.8 on the CVSS scale, enable privilege escalation and authentication bypass through malformed signatures, with patches available in versions 17.0.5 and 17.0.6.

Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators.

The vulnerabilities, as disclosed by Patchstack, are listed below -

CVE-2026-61979 (CVSS score: 8.1) - An unauthenticated privilege escalation

Read original article

*** END OF TRANSMISSION ***