HackerFeeds

CyberSecurity News

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

The Hacker News
· August 25, 2026

AI summary

Attackers are exploiting two severe vulnerabilities in the Xecurify miniOrange SAML 2.0 Single Sign On plugin, which can allow them to bypass authentication and sign in as any WordPress user, including administrators. The vulnerabilities, disclosed by Patchstack, include CVE-2026-61979, an unauthenticated privilege escalation issue with a CVSS score of 8.1. This flaw can grant an attacker administrative access to a WordPress site. The vulnerabilities are being targeted by bad actors, putting WordPress sites that use the affected plugin at risk.

Vulnerabilities mentioned

Read the full article at The Hacker Newsthehackernews.com/2026/08/attackers-target-miniorange-saml-flaws.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.