#3
The Hacker News
general
August 25, 2026 at 08:34 UTC
Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
By [email protected] (The Hacker News)
AI Summary
Attackers are actively exploiting two unauthenticated authentication bypass vulnerabilities — CVE-2026-61979 (CVSS 8.1) and CVE-2026-15981 — in the Xecurify miniOrange SAML 2.0 Single Sign On WordPress plugin, allowing privilege escalation to administrator-level access. Any WordPress site using this plugin is at immediate risk of full compromise and should apply Patchstack-disclosed patches without delay.
Relevance score: 84.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →