Critical miniOrange SAML SSO Flaws Let Attackers Take Over WordPress Admin Accounts
Two critical vulnerabilities have been identified in the miniOrange SAML 2.0 Single Sign-On WordPress plugin, which could allow unauthenticated attackers to forge SAML assertions and log in as any existing user, including site administrators. These vulnerabilities, tracked as CVE-2026-61979 and CVE-2026-15981, carry a CVSS score of 9.8. Research conducted by DigitalOcean’s security team and later […]
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
