ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
CRITICAL Vulnerabilities

miniOrange SAML 2.0 flaw can let attackers log in as WordPress admin

Source headline: Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

Threat level Critical
Signal strength 80/100
Source confidence 1 source
Published 14 hours ago

Intelligence Summary

Attackers are targeting unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin. The flaws can allow an attacker to sign in as any WordPress user, including administrators. Patchstack lists the issue as CVE-2026-61979 with a CVSS score of 8.1. The vulnerability is described as an unauthenticated authentication/privilege escalation bypass. This matters because compromised accounts could lead to full administrative control. Patch and remediate the affected plugin installation immediately after applying the available fix.

Recommended Action

Check whether your miniOrange SAML 2.0 Single Sign On deployment is affected by CVE-2026-61979 (CVSS 8.1) and apply the vendor fix. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.

Topics

#cve #privilege-escalation #wordpress #miniorange #saml #unauthenticated-bypass
Original reporting The Hacker News Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
Open original source