WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities
Summary
Two authentication bypass vulnerabilities, CVE-2026-61979 and CVE-2026-15981, have been identified in the MiniOrange SAML 2.0 SSO plugin for WordPress. These vulnerabilities could allow unauthorized access to WordPress websites.
IFF Assessment
FOE
The discovery of authentication bypass vulnerabilities poses a direct threat to the security of WordPress websites, making it bad news for defenders.
Severity
9.8
Critical
Defender Context
Defenders should be aware of these vulnerabilities affecting a popular WordPress plugin and prioritize patching or implementing mitigation strategies for the MiniOrange SAML 2.0 SSO plugin. Monitoring for signs of exploitation is crucial, as authentication bypass flaws can be leveraged for initial access by threat actors.