Exploited in the wild WordPress auth-bypass MiniOrange SAML 2.0 Single Sign-On plugin privilege-escalation
WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities
CVE Tools coverage
Threat actors are actively exploiting two critical authentication bypass vulnerabilities in the MiniOrange SAML 2.0 Single Sign-On plugin for WordPress, allowing attackers to log in as any user, including administrators. The flaws, identified as CVE-2026-61979 and CVE-2026-15981, affect a widely used plugin with over 10,000 installations of its free edition alone. While patches are available, the lack of clear security advisories for paid versions complicates remediation efforts, making active mitigation essential.