
Active Exploitation of MiniOrange SAML Plugin Vulnerabilities Targeting WordPress Sites
VulnerabilitiesexploitedMiniOrangeWordPressauthentication_bypassCVE
Two authentication bypass vulnerabilities, CVE-2026-61979 and CVE-2026-15981, are actively being exploited to target WordPress websites using the MiniOrange SAML 2.0 SSO plugin. The flaws affect the plugin’s implementation, allowing attackers to bypass authentication mechanisms. No specific timeline, attack scale, or impacted versions were disclosed in the report. The vulnerabilities were identified as part of ongoing exploitation campaigns against WordPress sites. The MiniOrange plugin is the primary component involved in the attacks.