WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities

WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities
Threat actors are opportunistically exploiting two patched MiniOrange SAML 2.0 Single Sign-On vulnerabilities, CVE-2026-61979 and CVE-2026-15981, to bypass authentication on WordPress sites. The silent patching approach and inconsistent versioning for paid editions make it difficult for site owners to know whether they are protected. #CVE-2026-61979 #CVE-2026-15981 #MiniOrange

Keypoints

  • Two MiniOrange SAML 2.0 SSO flaws are being actively exploited.
  • The vulnerabilities allow attackers to log in as any WordPress user, including administrators.
  • The free plugin edition is installed on more than 10,000 WordPress sites.
  • Patchstack says the attacks appear opportunistic, not targeted.
  • Paid edition users were not clearly notified about the security fixes.

Read More: https://www.securityweek.com/wordpress-websites-targeted-via-miniorange-plugin-vulnerabilities/