Skip to content
feed: live
>_0dayNews
CVE Record
[ HIGH ]CVE-2026-61979

miniOrange SAML 2.0 SSO — Second Authentication Bypass (High)

High-severity auth bypass in miniOrange SAML 2.0 SSO for WordPress; being exploited alongside critical CVE-2026-15981 in active attack campaigns.

cat cve-2026-61979.json
Vendor
Xecurify
Product
miniOrange SAML 2.0 Single Sign On
CVSS
8.1
EPSS (exploit probability)
N/A
Status
exploited-in-wild
Published

Second unauthenticated authentication bypass in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, reported alongside CVE-2026-15981 (CVSS 9.8, Critical). Both vulnerabilities affect the same plugin and are being actively exploited in tandem.

Impact: Authentication bypass allowing access as arbitrary WordPress users. Combined with CVE-2026-15981, attackers have two separate mechanisms to achieve unauthorized access; the pair increases the attack surface and complicates any partial mitigations.

Affected product: Xecurify’s miniOrange SAML 2.0 Single Sign On plugin for WordPress. Consult the vendor advisory for affected version ranges.

Exploitation status: Active exploitation attempts confirmed per SecurityWeek and The Hacker News reporting (August 25, 2026).

Patch: Update the plugin immediately via Plugins → Updates in the WordPress dashboard. If patching cannot happen immediately, deactivate the plugin.

Post-patch steps: Audit administrator account list. Review recent login logs for unauthorized admin-level sessions.

See full coverage: miniOrange SAML WordPress Flaws Under Active Exploit