LIVE · cybersecurity feed
Live wire
vendor

Miniorange

1 CVEs published in the last four months and 3 stories. Exploited flaws first.

Critical0
High1
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-53437.4highsaml sso - service providerImproper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAML SSO - Service Provider allows Pri135d ago

Filter the full tracker by Miniorange →

Our coverage of Miniorange

CVE-2026-61979critical

Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable

Two critical authentication bypass vulnerabilities, both rated CVSS 9.8, in the miniOrange SAML 2.0 Single Sign On WordPress plugin were actively exploited before public vulnerability databases accurately reflected the affected paid editions. These flaws, identified as CVE-2026-61979 and CVE-2026-15981, allowed unauthenticated attackers to forge SAML authentication responses and gain…

CVE-2026-61979

WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities

Reports indicate that WordPress websites are currently being targeted through the exploitation of two authentication bypass vulnerabilities found in the MiniOrange SAML 2.0 SSO plugin. These vulnerabilities have been assigned the identifiers CVE-2026-61979 and CVE-2026-15981. The active targeting suggests that attackers are leveraging these flaws to gain unauthorized access to affected…

vulnerabilitycritical

Hackers target WordPress sites in miniOrange auth bypass attacks

Threat actors are actively attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. These vulnerabilities, tracked as CVE-2026-61979 and CVE-2026-15981, can be chained together to forge SAML responses and gain administrative access to affected WordPress sites.