Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable
ID: 8084fd9b-d563-5063-9f98-58a36119f0ec
STIX ID: report--8084fd9b-d563-5063-9f98-58a36119f0ec
Feed Name: Security Affairs
Two CVSS 9.8 authentication-bypass vulnerabilities in the miniOrange SAML 2.0 WordPress plugin (CVE-2026-61979 and CVE-2026-15981) have been actively exploited to forge SAML responses and obtain administrator sessions; vendor edition/versioning complexity caused paid editions to be reported as patched despite vulnerable code remaining, forcing manual hotfixes and prompting coordination between DigitalOcean, Patchstack, and miniOrange to publish mitigations and indicators (including scanning IPs).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
