Security
Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
The Hacker News·August 25, 2026·1 min read
Attackers are exploiting two unauthenticated authentication bypass vulnerabilities in the Xecurify miniOrange SAML 2.0 Single Sign On plugin, allowing them to sign in as any WordPress user, including administrators. The flaws, disclosed by Patchstack, include CVE-2026-61979 with a CVSS score of 8.1, enabling unauthenticated privilege escalation.
Read at The Hacker NewsDaily crypto arcade
Read the news, then play it.
Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.
