Hackers are targeting WordPress sites that use the miniOrange SAML SSO plugin and can use the flaws to sign in as site administrators. The attacks chain CVE-2026-61979 and CVE-2026-15981 to forge SAML login responses in miniOrange SAML 2.0 Single Sign On plugin editions from Xecurify; Patchstack says exploitation and scanning are underway, a public proof-of-concept exists, and patched versions were released in July, including Free 5.4.5 and multiple paid-edition updates.
Why it matters: A successful attack can give outsiders full admin access to a website, which can lead to malware, defacement, data theft, or account takeover. Sites using affected miniOrange editions should manually verify and install the patched version now, especially because paid editions may not show update warnings in the WordPress dashboard.
Eduard Kovacs
2026.08.25
99% relevant
This article directly updates the same event by reporting opportunistic exploitation attempts against the recently patched MiniOrange SAML 2.0 SSO flaws, adding detail that users of paid editions may not have been notified and may need to manually update because the fixes were effectively silent.
info@thehackernews.com (The Hacker News)
2026.08.25
99% relevant
This article covers the same active-attack event: exploitation of miniOrange WordPress SAML SSO flaws that enable administrator login on affected sites, reinforcing the exploitation status and affected plugin context.
Bill Toulas
2026.08.24
100% relevant
This article establishes a distinct tracked event: in-the-wild exploitation of two specific miniOrange WordPress SAML authentication-bypass flaws, with observed attacks, affected versions, and mitigation details.
← Back to all stories