logo

Critical miniOrange SAML SSO Vulnerabilities Allow WordPress Admin Takeover

ID: b73b667a-5cc4-5cce-a0f9-6e6218b92bd9

STIX ID: report--b73b667a-5cc4-5cce-a0f9-6e6218b92bd9

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-08-24

Date Updated: 2026-08-25

...
...

Two critical authentication-bypass vulnerabilities (CVE-2026-61979 and CVE-2026-15981) were disclosed in the miniOrange SAML 2.0 WordPress plugin (CVSS 9.8), enabling unauthenticated attackers to forge SAML assertions and assume any user account, including administrators. Exploitation has been observed in the wild, a public proof-of-concept for the free edition is available, and vendor advisories did not fully cover paid editions—site owners must manually apply patches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.