[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fu1Bcp5PF3rExuarESxzahKTq5jFHU3EIPw9mMbKlSio":3},{"article":4,"iocs":45},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":27,"category":28,"article_tags":32},"de0bcb9e-2b81-402d-a09d-3f85b132ff35","WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities","wordpress-websites-targeted-via-miniorange-plugin-vulnerabilities-fd0726","CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin. The post WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities appeared first on SecurityWeek.","Threat actors are actively exploiting two critical authentication bypass vulnerabilities, CVE-2026-61979 and CVE-2026-15981, in the MiniOrange SAML 2.0 Single Sign-On (SSO) plugin for WordPress. These flaws allow attackers to log in as any user, including administrators. While patches exist, the developer's lack of clear communication, especially for paid versions, leaves many users unaware and vulnerable to these opportunistic attacks.","WordPress websites are targeted by attackers exploiting two critical authentication bypass vulnerabilities in the","Threat actors have been attempting to hack WordPress websites by exploiting two recently patched vulnerabilities affecting a MiniOrange plugin. The two vulnerabilities are CVE-2026-61979 and CVE-2026-15981, and they affect the MiniOrange SAML 2.0 Single Sign-On (SSO) plugin, which enables SSO for WordPress websites. The free edition of the plugin is installed on more than 10,000 WordPress sites, but there are also several paid and enterprise versions for which usage statistics are not available. According to an analysis conducted by DigitalOcean and security firm Patchstack, the vulnerabilities are critical authentication bypasses that can be exploited to log in as any WordPress user, including administrators. Threat actors have been attempting to exploit CVE-2026-61979 and CVE-2026-15981 in what Patchstack described as opportunistic attacks rather than a targeted campaign. The problem is that while all affected versions of the MiniOrange SAML 2.0 SSO plugin have been patched, the developer has not warned users about the potential risks. Only the free edition has an advisory that mentions the fix in version 5.4.5, but it’s listed as a bugfix rather than a security patch. Advertisement. Scroll to continue reading. In the case of the paid editions, users have not been notified and a different versioning system makes it difficult to tell whether a website is patched; users have to manually update the plugin. “Whoever is running this appears to be throwing the exploit at every site with the plugin installed without checking which edition or version is behind it,” Patchstack warned. “This is exactly the behavior that makes the silent-patch situation dangerous. The attacker does not need to know which edition you run, you do.” SecurityWeek has reached out to the developer for comment and will update this article if it responds. Related: 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw Related: WordPress 7.0.4 Patches Remote Code Execution Vulnerability Related: WP2Shell WordPress Vulnerabilities Exploited in the Wild Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs 91 Vulnerabilities Patched in Spring Application FrameworkVenezuelan Gets Record Federal Prison Term for ATM JackpottingPersonal Information Exposed in Apollo Global Data BreachAnthropic Expands Mythos 5 Access to More Defenders, Unveils $35M Open Source FundBanking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the SpotlightContractors’ CMMC Confidence Rises as Ability to Prove It Falls BehindHackers Target Zimbra Servers in Active Exploitation CampaignOpenAI Overhauls Model Security With Sandboxing, 30-Minute Alerts, and Training Pauses Latest News WhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security UpdateHands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity ConferenceFirst Malware Built Specifically for Car Head Units Fuels BotnetSilent Patches Don’t Stop Attackers – They Blind DefendersTaiwan Charges 9 Over Illegal AI Server Exports to China, Including Nvidia and Super Micro StaffCISA Warns of Exploited Oracle WebLogic VulnerabilityReliaQuest Confirms ShinyHunters Hack, but Says Impact Was LimitedHired for One Job, Judged on Another: The CISO’s Real Problem Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Scaling AI Security August 26, 2026 Join this live webinar for a practical framework for evolving your AI security program from a single application to an enterprise AI ecosystem and autonomous agents. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveDevi Nair has been appointed Director of Cybersecurity Programs at Aspen Digital.Forcepoint has named Proofpoint veteran Vincent Merlin as its new Chief Marketing Officer.Vensure Employer Solutions appointed Michael Lockhart as Chief Information Security Officer.More People On The MoveExpert Insights Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Rethinking Application Security for the AI Era As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk. (Joshua Goldfarb) The AI Governance Gap Is a Leadership Problem: Waiting Won’t Close It Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. (Steve Durbin) Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Flipboard Reddit Whatsapp Whatsapp Email","https:\u002F\u002Fwww.securityweek.com\u002Fwordpress-websites-targeted-via-miniorange-plugin-vulnerabilities\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2024\u002F08\u002FWordPress.jpeg","2026-08-25T13:33:12+00:00","2026-08-25T14:00:06.835548+00:00",8,[18,21,24],{"name":19,"type":20},"SAML 2.0 SSO plugin","product",{"name":22,"type":23},"MiniOrange","vendor",{"name":25,"type":26},"WordPress","technology","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":27,"icon":29,"name":30,"slug":31},null,"Vulnerabilities","vulnerabilities",[33,35,40],{"category":34},{"id":27,"icon":29,"name":30,"slug":31},{"category":36},{"id":37,"icon":29,"name":38,"slug":39},"ade75414-7914-4e23-a450-48b64546ee70","Open Source","open-source",{"category":41},{"id":42,"icon":29,"name":43,"slug":44},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[46,50],{"type":47,"value":48,"context":49},"cve","CVE-2026-61979","Authentication bypass vulnerability in MiniOrange SAML 2.0 SSO plugin",{"type":47,"value":51,"context":49},"CVE-2026-15981"]