CVE Tools

WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities

SecurityWeekBy Eduard Kovacs

Reported exploitedWordPressMiniOrange SAML 2.0 Single Sign-On plugin

Our summary

Threat actors are actively exploiting two critical authentication bypass vulnerabilities in the MiniOrange SAML 2.0 Single Sign-On plugin for WordPress, allowing attackers to log in as any user, including administrators. The flaws, identified as CVE-2026-61979 and CVE-2026-15981, affect a widely used plugin with over 10,000 installations of its free edition alone. While patches are available, the lack of clear security advisories for paid versions complicates remediation efforts, making active mitigation essential.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store