Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

August 25, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: WordPress site administrators using miniOrange SAML plugin
Incident: Active exploitation of CVE-2026-61979 and CVE-2026-15981 in the miniOrange SAML plugin.
Impact: Complete site takeover through unauthorized administrative access.
Attacker: Unidentified opportunistic threat actors
Analysis: Attackers are leveraging signature algorithm confusion and malformed signature validation to bypass authentication. By manipulating SAML responses, unauthenticated users can impersonate any account, including site administrators. The availability of a public PoC has accelerated opportunistic scanning across the web.
Recommendations: Update miniOrange SAML plugin to version 17.0.6 or newer immediately.; Review WordPress admin logs for anomalous login sessions from untrusted IPs.; Implement restrictive network access controls for administrative panels.
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *