Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
Overview
Attackers are exploiting two serious vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, allowing unauthorized users to log in as any WordPress user, including those with administrative privileges. These vulnerabilities, identified as CVE-2026-61979, have a CVSS score of 8.1, indicating a high severity level. This situation puts numerous WordPress sites at risk, as it could enable attackers to gain complete control over these sites without needing valid credentials. The vulnerabilities were disclosed by Patchstack, underscoring the need for site administrators to take immediate action. Promptly addressing these flaws is crucial to prevent unauthorized access and potential data breaches.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: miniOrange SAML 2.0 Single Sign On plugin for WordPress
- Action Required: WordPress site administrators should immediately update the miniOrange SAML 2.
- Timeline: Newly disclosed
Original Article Summary
Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators. The vulnerabilities, as disclosed by Patchstack, are listed below - CVE-2026-61979 (CVSS score: 8.1) - An unauthenticated privilege escalation
Impact
miniOrange SAML 2.0 Single Sign On plugin for WordPress
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Newly disclosed
Remediation
WordPress site administrators should immediately update the miniOrange SAML 2.0 Single Sign On plugin to the latest version that addresses these vulnerabilities. Additionally, they should review user access logs and consider implementing multi-factor authentication to enhance security.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Exploit, Vulnerability, and 1 more.