<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[🟠 High: Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access]]></title><description><![CDATA[<p dir="auto">Active exploitation is underway targeting two unauthenticated authentication bypass flaws in the Xecurify miniOrange SAML 2.0 Single Sign On plugin for WordPress. The vulnerabilities, which were disclosed by Patchstack, allow attackers to bypass the authentication process entirely and log in as any user on the site—including users with administrator privileges.</p>
<p dir="auto">The first issue, <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-61979" target="_blank" rel="noopener noreferrer nofollow ugc">CVE-2026-61979</a>, carries a CVSS score of 8.1 and is described as an unauthenticated privilege escalation. This flaw stems from improper handling of the SAML response validation process, enabling a malicious actor to forge a valid session without needing valid credentials.</p>
<ul>
<li>The second vulnerability has not been disclosed with a specific CVE identifier in the reporting, but it is similarly severe, involving an authentication bypass that can be chained with the first to achieve full account takeover.</li>
<li>Successful exploitation grants the attacker the exact role and capabilities of the targeted user account, meaning a single compromised request can lead to complete site compromise if an admin account is hijacked.</li>
</ul>
<p dir="auto">WordPress administrators using the <strong>miniOrange SAML 2.0 Single Sign On</strong> plugin should verify they are running the latest patched version immediately. Given that this is an unauthenticated attack vector, there is no indication of prior access required, making it a critical risk for any site with the plugin active.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/08/attackers-target-miniorange-saml-flaws.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Is your team already tracking this plugin's update status, or are you relying on a WAF to mitigate these bypass attempts before a patch is applied?</p>
]]></description><link>https://xploitlk.com/topic/94/high-attackers-target-miniorange-saml-flaws-that-can-grant-wordpress-admin-access</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 14:23:45 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/94.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 25 Aug 2026 10:30:23 GMT</pubDate><ttl>60</ttl></channel></rss>