Hackers target WordPress sites in miniOrange auth bypass attacks
ID: 7389f4c8-e706-5162-b574-f8553370b951
STIX ID: report--7389f4c8-e706-5162-b574-f8553370b951
Feed Name: Bleeping Computer
Threat Score
Hackers are exploiting two chained authentication-bypass vulnerabilities in the miniOrange SAML 2.0 SSO WordPress plugin (CVE-2026-61979 and CVE-2026-15981) to forge SAML responses and obtain administrator access. A public PoC exists, exploitation and opportunistic scanning have been observed from multiple IPs, and some paid plugin editions were not clearly notified of fixes, leaving many sites exposed; site owners must manually upgrade to patched versions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
