WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities

https://www.securityweek.com/wp-content/uploads/2024/08/WordPress.jpeg

Threat actors have been attempting to hack WordPress websites by exploiting two recently patched vulnerabilities affecting a MiniOrange plugin.

The two vulnerabilities are CVE-2026-61979 and CVE-2026-15981, and they affect the MiniOrange SAML 2.0 Single Sign-On (SSO) plugin, which enables SSO for WordPress websites.

The free edition of the plugin is installed on more than 10,000 WordPress sites, but there are also several paid and enterprise versions for which usage statistics are not available.

According to an analysis conducted by DigitalOcean and security firm Patchstack, the vulnerabilities are critical authentication bypasses that can be exploited to log in as any WordPress user, including administrators.

Threat actors have been attempting to exploit CVE-2026-61979 and CVE-2026-15981 in what Patchstack described as opportunistic attacks rather than a targeted campaign.

The problem is that while all affected versions of the MiniOrange SAML 2.0 SSO plugin have been patched, the developer has not warned users about...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more