THREAT actors are targeting WordPress websites by exploiting two recent vulnerabilities in the MiniOrange SAML 2.0 Single Sign-On (SSO) plugin, identified as CVE-2026-61979 and CVE-2026-15981. These critical vulnerabilities enable authentication bypass, allowing attackers to log in as any WordPress user, including administrators. The free version of the plugin, installed on over 10,000 sites, has been patched, but users of paid versions have not been adequately notified about the risks or necessary updates.
The vulnerabilities have led to opportunistic attacks, prompting concerns regarding the lack of communication about these critical updates from the developer.