Dossier
CVE-2026-61979
Coverage of CVE-2026-61979 in the Nexus archive.
- Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin. These vulnerabilities make it possible for an attacker to sign in as any WordPress user, including administrators. Patchstack disclosed these flaws, which include CVE-2026-61979.