Recent findings from Patchstack reveal that attackers are actively exploiting two critical unauthenticated authentication bypass vulnerabilities in the Xecurify miniOrange SAML 2.0 Single Sign-On plugin, which could enable them to log in as any WordPress user, including those with administrative privileges. The identified vulnerability, CVE-2026-61979, has a high CVSS score of 8.1, indicating a severe risk that organizations using this plugin should take seriously to safeguard their systems.
For businesses utilizing the miniOrange SAML plugin, this revelation underscores the critical need for immediate action to mitigate the risks associated with these vulnerabilities. Organizations should assess their current security posture, apply necessary patches, and consider implementing additional security measures such as multi-factor authentication to further protect their WordPress instances. This incident highlights the growing trend of targeting authentication mechanisms within web applications, emphasizing the importance of robust security measures in the ongoing battle against cyber threats, particularly in the realms of cybersecurity and AI where trust and data integrity are paramount.
---
*Originally reported by [The Hacker News](https://thehackernews.com/2026/08/attackers-target-miniorange-saml-flaws.html)*