Threat Intelligence

Hackers Actively Exploiting WordPress SAML Login Plugin Flaws

The Hacker News · 25 Aug 2026
Key Takeaway If your business website runs WordPress with the miniOrange SAML SSO plugin, update it immediately and review admin account activity for signs of unauthorised access.

Security researchers have detected active exploitation attempts against two severe vulnerabilities in the Xecurify miniOrange SAML 2.0 Single Sign On plugin for WordPress. These flaws allow attackers to bypass authentication entirely and log in as any user on an affected site, including site administrators, without needing a password.

One of the disclosed issues, CVE-2026-61979, carries a high CVSS score of 8.1 and was identified as an unauthenticated privilege escalation vulnerability. Because the plugin is used to manage single sign-on for WordPress sites, successful exploitation could give attackers full administrative control, enabling them to install malicious plugins, steal data, or take over the website entirely.

WordPress remains one of the most widely used content management systems among small and medium businesses in Australia, making plugin vulnerabilities like this a significant risk. Site owners using the miniOrange SAML SSO plugin should check for available patches immediately and apply updates as soon as they are released, given that active exploitation is already underway.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.