Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    CISA Warns of Exploited Gitea Vulnerability

    August 26, 2026

    Mini Brains Grown for Five Years Matured Like Human Brains

    August 26, 2026

    Marvel Tokon: Fighting Souls review: unlimited potential

    August 26, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities
    WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities
    Cybersecurity

    WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities

    The Tech GuyBy The Tech GuyAugust 25, 2026No Comments2 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    Threat actors have been attempting to hack WordPress websites by exploiting two recently patched vulnerabilities affecting a MiniOrange plugin.

    Advertisement

    The two vulnerabilities are CVE-2026-61979 and CVE-2026-15981, and they affect the MiniOrange SAML 2.0 Single Sign-On (SSO) plugin, which enables SSO for WordPress websites. 

    The free edition of the plugin is installed on more than 10,000 WordPress sites, but there are also several paid and enterprise versions for which usage statistics are not available. 

    According to an analysis conducted by DigitalOcean and security firm Patchstack, the vulnerabilities are critical authentication bypasses that can be exploited to log in as any WordPress user, including administrators. 

    Threat actors have been attempting to exploit CVE-2026-61979 and CVE-2026-15981 in what Patchstack described as opportunistic attacks rather than a targeted campaign. 

    The problem is that while all affected versions of the MiniOrange SAML 2.0 SSO plugin have been patched, the developer has not warned users about the potential risks. Only the free edition has an advisory that mentions the fix in version 5.4.5, but it’s listed as a bugfix rather than a security patch. 

    Advertisement. Scroll to continue reading.

    In the case of the paid editions, users have not been notified and a different versioning system makes it difficult to tell whether a website is patched; users have to manually update the plugin.

    “Whoever is running this appears to be throwing the exploit at every site with the plugin installed without checking which edition or version is behind it,” Patchstack warned. “This is exactly the behavior that makes the silent-patch situation dangerous. The attacker does not need to know which edition you run, you do.”

    SecurityWeek has reached out to the developer for comment and will update this article if it responds.

    Related: 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw

    Related: WordPress 7.0.4 Patches Remote Code Execution Vulnerability

    Related: WP2Shell WordPress Vulnerabilities Exploited in the Wild

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    CISA Warns of Exploited Gitea Vulnerability

    August 26, 2026

    Alice Raises $140M to Expand AI Model Defenses and Enterprise Guardrails

    August 26, 2026

    Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation

    August 25, 2026

    91 Vulnerabilities Patched in Spring Application Framework

    August 25, 2026

    Hired for One Job, Judged on Another: The CISO’s Real Problem

    August 25, 2026

    ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited

    August 24, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026391 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026210 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    CISA Warns of Exploited Gitea Vulnerability

    August 26, 2026

    Mini Brains Grown for Five Years Matured Like Human Brains

    August 26, 2026

    Marvel Tokon: Fighting Souls review: unlimited potential

    August 26, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.