logo

Hackers target WordPress sites in miniOrange auth bypass attacks

ID: 7389f4c8-e706-5162-b574-f8553370b951

STIX ID: report--7389f4c8-e706-5162-b574-f8553370b951

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-08-24

Date Updated: 2026-08-24

Author: Bill Toulas

...
...

Hackers are exploiting two chained authentication-bypass vulnerabilities in the miniOrange SAML 2.0 SSO WordPress plugin (CVE-2026-61979 and CVE-2026-15981) to forge SAML responses and obtain administrator access. A public PoC exists, exploitation and opportunistic scanning have been observed from multiple IPs, and some paid plugin editions were not clearly notified of fixes, leaving many sites exposed; site owners must manually upgrade to patched versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.