logo

Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable

ID: 8084fd9b-d563-5063-9f98-58a36119f0ec

STIX ID: report--8084fd9b-d563-5063-9f98-58a36119f0ec

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

Author: Pierluigi Paganini

...
...

Two CVSS 9.8 authentication-bypass vulnerabilities in the miniOrange SAML 2.0 WordPress plugin (CVE-2026-61979 and CVE-2026-15981) have been actively exploited to forge SAML responses and obtain administrator sessions; vendor edition/versioning complexity caused paid editions to be reported as patched despite vulnerable code remaining, forcing manual hotfixes and prompting coordination between DigitalOcean, Patchstack, and miniOrange to publish mitigations and indicators (including scanning IPs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.