Hackers Exploit Critical miniOrange SAML SSO Flaws to Hijack WordPress Admin Accounts

Two critical flaws in the miniOrange SAML 2.0 Single Sign-On plugin could allow unauthenticated attackers to log in to vulnerable WordPress sites as any existing user, including administrators. The flaws, tracked as CVE-2026-61979 and CVE-2026-15981, carry a CVSS score of 9.8 and have been linked to attempted exploitation activity in the wild. The vulnerabilities affect […]

This article has been indexed from Cyber Security News

Read the original article: