Attackers are targeting WordPress sites using two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin, which can allow unauthorized users to log in as WordPress administrators. Multiple reports describe the issues as being exploitable without prior authentication, enabling attackers to obtain elevated access.
The vulnerabilities are associated with forged or improperly validated SAML authentication responses. Patchstack disclosure is referenced in reporting, with one flaw identified as CVE-2026-61979 (CVSS 8.1), described as an unauthenticated privilege escalation. Coverage differs mainly in emphasis: one outlet focuses on the authentication bypass being used to forge SAML responses and achieve administrator login, while another highlights the broader ability to sign in as any WordPress user. Both describe the miniOrange SAML plugin as the affected component and frame the activity as active targeting of WordPress deployments.
Overall, the reporting aligns on the core claim that the miniOrange plugin contains severe, unauthenticated weaknesses that can lead to account takeover and admin access, underscoring the need for timely mitigation and patching by site operators.