Skip to content
The Nexus
SECURITYAug 25 · 08:34 UTCTHE HACKER NEWS[email protected] (The Hacker News)

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin. These vulnerabilities make it possible for an attacker to sign in as any WordPress user, including administrators. Patchstack disclosed these flaws, which include CVE-2026-61979.

Nexus surfaces and summarizes. The full story lives at the source.

Mentioned
Spot something wrong with this article?Report a problem →
Forward this
Related Signal

Adjacent reporting