logo

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

ID: aa4b526f-5093-5d47-9bcc-865b9191306b

STIX ID: report--aa4b526f-5093-5d47-9bcc-865b9191306b

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

Author: [email protected] (The Hacker News)

...
...

Patchstack reported two critical unauthenticated authentication-bypass vulnerabilities in the Xecurify/miniOrange SAML 2.0 Single Sign On WordPress plugin (CVE-2026-61979 CVSS 8.1 and CVE-2026-15981 CVSS 9.8) that allow attackers to log in as any user by abusing signature verification flaws. Proof-of-concept code is available, and scanning activity from multiple IP addresses has been observed, so site owners should apply the vendor fixes immediately to prevent admin account takeover.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.