CyberSecurity News
Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
AI summary
Attackers are exploiting two severe vulnerabilities in the Xecurify miniOrange SAML 2.0 Single Sign On plugin, which can allow them to bypass authentication and sign in as any WordPress user, including administrators. The vulnerabilities, disclosed by Patchstack, include CVE-2026-61979, an unauthenticated privilege escalation issue with a CVSS score of 8.1. This flaw can grant an attacker administrative access to a WordPress site. The vulnerabilities are being targeted by bad actors, putting WordPress sites that use the affected plugin at risk.
Vulnerabilities mentioned
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

