Critical miniOrange SAML SSO Vulnerabilities Allow WordPress Admin Takeover
ID: b73b667a-5cc4-5cce-a0f9-6e6218b92bd9
STIX ID: report--b73b667a-5cc4-5cce-a0f9-6e6218b92bd9
Feed Name: ThreatCluster
Threat Score
Two critical authentication-bypass vulnerabilities (CVE-2026-61979 and CVE-2026-15981) were disclosed in the miniOrange SAML 2.0 WordPress plugin (CVSS 9.8), enabling unauthenticated attackers to forge SAML assertions and assume any user account, including administrators. Exploitation has been observed in the wild, a public proof-of-concept for the free edition is available, and vendor advisories did not fully cover paid editions—site owners must manually apply patches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
