Search

Find merged stories by title or summary.

Vulnerabilities & Patches
Emerging1 src

Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable

Two CVSS 9. 8 miniOrange SAML WordPress plugin auth bypasses were exploited while paid editions never appeared in any vulnerability database. Manual patch required. Two critical authentication bypass vulnerabilities in the miniOrange SAML 2. 0 Single Sign On WordPress plugin, both rated CVSS 9. 8, are under active exploitation. Both CVE-2026-61979 and CVE-2026-15981 allow an unauthenticated attacker to forge a SAML authentication response and arrive in /wp-admin as any existing user, including administrators. The bugs are independent and both have been confirmed exploited in the wild. CVE-2026-61979 is an algorithm confusion flaw. The plugin trusts the incoming SAML response to declare its own signature algorithm. An attacker sets that algorithm to HMAC-SHA1, which causes the plugin to use the identity provider’s RSA public key as the HMAC secret.

·Security Affairs
Read →
Vulnerabilities & Patches
Emerging1 src

WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities

CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin. The post WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities appeared first on SecurityWeek .

·SecurityWeek
Read →
Vulnerabilities & Patches
Emerging1 src

Critical WordPress SAML SSO Flaws Enable Unauthenticated Admin Account Takeover

Two critical vulnerabilities in the miniOrange SAML 2.0 Single Sign-On WordPress plugin could allow unauthenticated attackers to forge SAML assertions and access /wp-admin as any existing account, including administrators. The flaws, tracked as CVE-2026-61979 and CVE-2026-15981, carry a CVSS score of 9.8 and have reportedly been targeted by opportunistic scanning activity. DigitalOcean’s security team detected and blocked an anomalous WordPress administrator session attempt on its infrastructure, and then reproduced both bypasses in miniOrange’s Standard edition, version 16. 1. 9. Critical WordPress SAML SSO Flaws Patchstack coordinated vendor follow-up and expanded its vulnerability database coverage after discovering that the plugin’s distribution model obscured exposure across paid editions. CVE-2026-61979 stems from signature-algorithm confusion.

·CyberPress
Read →

You've reached the end of current stories for this search.