miniOrange SAML plugin under active exploitation
π Patchstack and DigitalOcean reported active exploitation attempts against miniOrange SAML 2.0 Single Sign On, where two unauthenticated flaws allow attackers to authenticate as any WordPress user, including admins. The issues are tracked as CVE-2026-61979 and CVE-2026-15981 and have been fixed in recent Standard edition updates. Owners are urged to update immediately due to available PoC code and observed opportunistic scanning from multiple IPs.
