vulnerability WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities Threat actors are actively exploiting two recently patched vulnerabilities within the MiniOrange SAML 2.0 Single Sign-On plugin for WordPress websites. These vulnerabilities allow attackers to bypass authentication and gain access to any WordPress user account, despite the fact that patches are available and the develo… SecurityWeek · 5d ago High CVE-2026-61979CVE-2026-15981wordpressvulnerabilityauthentication
vulnerability Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access Attackers are exploiting two unauthenticated vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, allowing them to gain administrator access to vulnerable sites. The vulnerabilities stem from f… The Hacker News · 5d ago High CVE-2026-61979CVE-2026-15981wordpresssamlauthentication