Diamond Member ThaHaka 0 Posted Tuesday at 08:34 AM Diamond Member Share Posted Tuesday at 08:34 AM This is the hidden content, please Sign In or Sign Up Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators. The vulnerabilities, as disclosed by Patchstack, are listed below - CVE-2026-61979 (CVSS score: 8.1) - An unauthenticated privilege escalation This is the hidden content, please Sign In or Sign Up 0 Quote Link to comment https://hopzone.eu/forums/topic/326733-h4ckn3wsattackers-target-miniorange-saml-flaws-that-can-grant-wordpress-admin-access/ Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.