Skip to main content
See every side of every news story
Published loading...Updated

Hackers target WordPress sites in miniOrange auth bypass attacks

Summary by BleepingComputer
Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators.

8 Articles

A critical flaw in the miniOrange SAML 2.0 Single Sign-On plugin places WordPress sites that use corporate authentication at risk of invasion. Two vulnerabilities, identified as CVE-2026-61979 and CVE-2026-15981, allow bypassing SAML signature validation mechanisms and, under certain conditions, make an unauthenticated attacker be treated as a legitimate user. The problem is especially serious because the plugin is used to integrate WordPress in…

New hack campaign against WordPress. This time, hackers use 2 faults present in the miniOrange SAML 2.0 Single Sign On plugin. This plugin is supposed to put in place an authentication and a mechanism of SSO avoiding entering the identifiers each time. The attack completely bypasses the mechanisms of the plugin! All WordPress sites using this plugin are potentially affected. The weakness comes from the SAML Assertion Consumer Service mechanism a…

Read Full Article
Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

BleepingComputer broke the news in Melville, United States on Monday, August 24, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal