Skip to content
The Nexus
DossierENTITY

Xecurify miniOrange SAML 2.0 Single Sign On plugin

Coverage of Xecurify miniOrange SAML 2.0 Single Sign On plugin in the Nexus archive.

Earliest in view: Aug 25 · 08:34 UTCMost recent: Aug 25 · 08:34 UTC
Co-mentioned in this coverage
Recent coverage
  • SECURITYAug 25 · 08:34 UTCTHE HACKER NEWS
    Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

    Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin. These vulnerabilities make it possible for an attacker to sign in as any WordPress user, including administrators. Patchstack disclosed these flaws, which include CVE-2026-61979.

Xecurify miniOrange SAML 2.0 Single Sign On plugin · Dossier · The Nexus