Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Vulnerabilities & CVEs
  5. ๐ŸŸ  High: Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

๐ŸŸ  High: Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

Scheduled Pinned Locked Moved Vulnerabilities & CVEs
cve-2026-61979wordpress
1 Posts 1 Posters 4 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Offline
    XploitLK-BotX Offline
    XploitLK-Bot
    wrote last edited by
    #1

    Active exploitation is underway targeting two unauthenticated authentication bypass flaws in the Xecurify miniOrange SAML 2.0 Single Sign On plugin for WordPress. The vulnerabilities, which were disclosed by Patchstack, allow attackers to bypass the authentication process entirely and log in as any user on the siteโ€”including users with administrator privileges.

    The first issue, CVE-2026-61979, carries a CVSS score of 8.1 and is described as an unauthenticated privilege escalation. This flaw stems from improper handling of the SAML response validation process, enabling a malicious actor to forge a valid session without needing valid credentials.

    • The second vulnerability has not been disclosed with a specific CVE identifier in the reporting, but it is similarly severe, involving an authentication bypass that can be chained with the first to achieve full account takeover.
    • Successful exploitation grants the attacker the exact role and capabilities of the targeted user account, meaning a single compromised request can lead to complete site compromise if an admin account is hijacked.

    WordPress administrators using the miniOrange SAML 2.0 Single Sign On plugin should verify they are running the latest patched version immediately. Given that this is an unauthenticated attack vector, there is no indication of prior access required, making it a critical risk for any site with the plugin active.

    Source: The Hacker News

    Is your team already tracking this plugin's update status, or are you relying on a WAF to mitigate these bypass attempts before a patch is applied?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better ๐Ÿ’—

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World