CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions.

Two critical authentication bypass vulnerabilities (CVSS 9.8) in the miniOrange SAML 2.0 Single Sign On WordPress plugin have been actively exploited. These flaws allow unauthenticated attackers to forge SAML responses and gain administrative access. The vulnerabilities were particularly insidious because they affected paid editions of the plugin, which were not listed in public vulnerability databases and did not trigger automatic updates, leaving administrators unaware of their exposure.

CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin. The post WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities appeared first on SecurityWeek.