Skip to main content

Tag: miniorange

1 article

Laptop screen shows WordPress backend dashboard with security settings.

Hackers Exploit WordPress Sites in miniOrange Auth Bypass Attacks

Hackers are actively exploiting WordPress sites using a clever combination of two vulnerabilities, CVE-2026-61979 and CVE-2026-15981, to bypass authentication and gain administrator access. This stealthy attack uses the miniOrange SAML 2.0 Single Sign On plugin to forge SAML responses and hijack user sessions.

Analyst 207