The Financial Register.

Inward fraud & financial crime, explained for Gen Z

Live coverage / The Wire

Update · 10:38 am AEST · 25 August 2026

Hackers target WordPress sites in miniOrange authentication bypass attacks

Hackers target WordPress sites in miniOrange authentication bypass attacks
Photograph: BleepingComputer

Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, BleepingComputer reports.

The flaws, tracked as CVE-2026-61979 and CVE-2026-15981, can be chained together to forge SAML responses and log in as administrators, according to security firm Patchstack.

Hackers target WordPress sites in miniOrange auth bypass attacks Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. bleepingcomputer.com
cybersecurityvulnerabilitieswordpressscams

Follow the live coverage →

Hackers target WordPress sites in miniOrange authentication bypass attacks | The Financial Register Inward Money