By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Attackers Exploit miniOrange SAML Flaws for WordPress Admin Access

Attackers are actively attempting to exploit two severe unauthenticated authentication bypass vulnerabilities within the Xecurify miniOrange SAML 2.0 Single Sign On plugin. These flaws enable malicious actors to bypass authentication mechanisms and log in as any WordPress user, including administrators, according to disclosures by Patchstack. The vulnerabilities, identified as CVE-2026-61979 and CVE-2026-61980, carry significant risk due to their unauthenticated nature and potential for privilege escalation. CVE-2026-61979, with a CVSS score of 8.1, specifically addresses an unauthenticated privilege escalation issue. The second vulnerability, CVE-2026-61980, also allows for unauthenticated access, further exacerbating the security risk. The miniOrange SAML 2.0 Single Sign On plugin is designed to simplify user authentication by enabling Single Sign-On (SSO) capabilities, often integrating with enterprise identity providers. However, these newly discovered flaws undermine its security, turning a tool meant to enhance security and user experience into a critical attack vector. The exploitation of these vulnerabilities could lead to complete compromise of WordPress websites, allowing attackers to deface sites, steal sensitive data, deploy malware, or use the compromised site for further malicious activities. Patchstack, a security company specializing in web application security, has been instrumental in identifying and reporting these issues. Their analysis highlights the critical nature of these bypasses, emphasizing that an attacker does not need any prior credentials or user accounts to exploit them. The CVSS (Common Vulnerability Scoring System) score of 8.1 for CVE-2026-61979 indicates a high severity, suggesting that exploitation is feasible and the impact is substantial. The lack of authentication required for exploitation means that any internet-connected attacker could potentially target vulnerable WordPress installations. The implications for businesses and individuals relying on WordPress for their online presence are significant, as a successful exploit could result in irreversible damage to reputation and data integrity. Website administrators are strongly advised to check for updates to the miniOrange SAML 2.0 Single Sign On plugin and apply any available patches immediately. The disclosure by Patchstack serves as a crucial alert to the WordPress security community and users of the affected plugin, underscoring the ongoing need for vigilance and prompt security patching in web application environments. The ease with which these vulnerabilities can be exploited, coupled with the high-impact outcome of gaining administrative control, makes this a pressing security concern for the WordPress ecosystem.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.