Vulnerabilities & Patching
Attackers Exploit miniOrange SAML SSO WordPress Flaws to Log In as Any Admin
Attackers are opportunistically exploiting two unauthenticated bypasses in the miniOrange SAML 2.0 SSO plugin, CVE-2026-61979 and CVE-2026-15981, to sign in as any WordPress user including administrators. A silent, multi-edition patch means your dashboard may wrongly report you as safe.