CVE Tools
Back to feed
Exploited in the wild WordPress auth-bypass MiniOrange SAML 2.0 Single Sign-On plugin privilege-escalation

WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities

SecurityWeek·By Eduard Kovacs··1 min read
CVE Tools coverage

Threat actors are actively exploiting two critical authentication bypass vulnerabilities in the MiniOrange SAML 2.0 Single Sign-On plugin for WordPress, allowing attackers to log in as any user, including administrators. The flaws, identified as CVE-2026-61979 and CVE-2026-15981, affect a widely used plugin with over 10,000 installations of its free edition alone. While patches are available, the lack of clear security advisories for paid versions complicates remediation efforts, making active mitigation essential.