CuraSec

Plan active

Attackers Targeting miniOrange SAML WordPress Plugin Auth Bypass

2026-08-25 11:39 UTC · The Hacker News · read the source ↗ #wordpress#saml#privilege-escalation
  • Engineer — Plan: If you run the miniOrange SAML 2.0 SSO WordPress plugin, update it immediately — unauthenticated privilege escalation to admin is high-severity, and active exploitation is claimed by Patchstack, though enrichment signals (EPSS 0.00, no KEV) don’t corroborate it yet.
  • SOC/IR — Learn: No IOCs, ATT&CK mappings, or behavioral TTPs are published; if your estate includes WordPress with SAML SSO, note this as a precursor to watching for unexpected admin account creation, but there is no actionable detection surface today.
  • Leader — Skip
  • Signals: CVE-2026-61979 — CISA KEV: not listed, EPSS 0.00, no public PoC found
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.