National Cyber Warfare Foundation (NCWF)

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access


0 user ratings
2026-08-25 09:43:03
milo
Attacks
Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators.

The vulnerabilities, as disclosed by Patchstack, are listed below -


CVE-2026-61979 (CVSS score: 8.1) - An unauthenticated privilege escalation



Source: TheHackerNews
Source Link: https://thehackernews.com/2026/08/attackers-target-miniorange-saml-flaws.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Attacks



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.