MiniOrange SAML 2.0 Single Sign On plugin for WordPress authentication bypass flaws (multiple vulnerabilities)
Vulnerability
Updated: 24.08.2026 22:26
· First: 24.08.2026 22:26
· 📰 1 src / 1 articles
· H score: 33
miniOrange SAML 2.0 Single Sign On plugin for WordPress has two authentication bypass vulnerabilities that are being actively exploited and can be chained to let attackers log in as administrators on affected sites. The flaws are tracked as CVE-2026-61979 and CVE-2026-15981, and a public PoC exploit increases the risk of wider abuse.