Critical miniOrange SAML SSO Flaws Let Attackers Take Over WordPress Admin Accounts
ID: 797e496d-aafc-5205-b148-23d9c7c34b50
STIX ID: report--797e496d-aafc-5205-b148-23d9c7c34b50
Feed Name: GBHackers
Two critical SAML authentication-bypass vulnerabilities (CVE-2026-61979 and CVE-2026-15981; CVSS 9.8) were found in the miniOrange SAML 2.0 WordPress plugin allowing forged SAML assertions and potential administrator takeover; the flaws affect the free and multiple paid, independently-versioned editions (causing patching/scan gaps), active opportunistic scanning and a public proof-of-concept were observed, and vendors/maintainers have released edition-specific patched versions while recommending manual upgrades or temporary mitigations (restrict /wp-admin, review logs, investigate admin sessions).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
