WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities
BLUF
Immediate patching is required due to active exploitation of critical authentication bypass vulnerabilities.
NEWS
CVE-2026-61979 and CVE-2026-15981 affect the MiniOrange SAML 2.0 SSO plugin, allowing attackers to bypass login security. Security Week reports that WordPress sites using this plugin are currently being targeted by threat actors.
Why I Care
Successful exploitation grants attackers full administrative access without valid credentials, compromising site integrity and user data. Any organization relying on this plugin for Single Sign-On is exposed to significant risk.
Next Steps
Update the MiniOrange SAML 2.0 SSO plugin to the latest version immediately. Audit all WordPress installations for this plugin and monitor access logs for suspicious activity within the next 24 hours.
Source: Security Week ·