CVE Tools

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

The Hacker NewsBy The Hacker News

Reported exploitedminiOrange SAML 2.0 Single Sign On pluginWordPress

Our summary

Attackers are actively targeting the Xecurify miniOrange SAML 2.0 Single Sign On plugin for WordPress, leveraging two critical flaws to assume administrative control of vulnerable sites. The campaign exploits CVE-2026-61979 and CVE-2026-15981, which stem from a flawed signature validation process that incorrectly treats malformed inputs as successful verifications, enabling unauthorized session creation. Since a proof-of-concept exists for these authentication bypasses, site administrators should immediately update to version 17.0.6 of the Standard edition to mitigate this high-risk threat.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store