Home / Aug 26, 2026 / Story
0
#3 The Hacker News general August 25, 2026 at 08:34 UTC

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

By [email protected] (The Hacker News)

AI Summary

Attackers are actively exploiting two unauthenticated authentication bypass vulnerabilities — CVE-2026-61979 (CVSS 8.1) and CVE-2026-15981 — in the Xecurify miniOrange SAML 2.0 Single Sign On WordPress plugin, allowing privilege escalation to administrator-level access. Any WordPress site using this plugin is at immediate risk of full compromise and should apply Patchstack-disclosed patches without delay.

Relevance score: 84.0/100

# More from August 26