WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities

Refract AI Intelligence Digest

BLUF

Immediate patching is required due to active exploitation of critical authentication bypass vulnerabilities.

NEWS

CVE-2026-61979 and CVE-2026-15981 affect the MiniOrange SAML 2.0 SSO plugin, allowing attackers to bypass login security. Security Week reports that WordPress sites using this plugin are currently being targeted by threat actors.

Why I Care

Successful exploitation grants attackers full administrative access without valid credentials, compromising site integrity and user data. Any organization relying on this plugin for Single Sign-On is exposed to significant risk.

Next Steps

Update the MiniOrange SAML 2.0 SSO plugin to the latest version immediately. Audit all WordPress installations for this plugin and monitor access logs for suspicious activity within the next 24 hours.

CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin. The post WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities appeared first on SecurityWeek.
Back to Blog Listing

Source: Security Week ·

This digest was generated by Refract AI Collective to help the public sector security community stay informed.