Login
← All news

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

The Hacker News Security WordPress

Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators. The vulnerabilities, as disclosed by Patchstack, are listed below - CVE-2026-61979 (CVSS score: 8.1) - An unauthenticated privilege escalation…

Read the full story on The Hacker News https://thehackernews.com/2026/08/attackers-target-miniorange-saml-flaws.html
Most WordPress sites are compromised through something ordinary: an unpatched plugin, an abandoned theme, an account without two-factor. If you would rather updates and backups simply happened, CrockyHost hosting does them for you.