Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit Vulnerabilities in MiniOrange WordPress Plugin

Hackers Exploit Vulnerabilities in MiniOrange WordPress Plugin

Posted on August 25, 2026 By CWS

Hackers are actively seeking to compromise WordPress websites by leveraging two newly addressed vulnerabilities found in a MiniOrange plugin. These flaws affect the SAML 2.0 Single Sign-On (SSO) plugin, a tool that facilitates single sign-on capabilities for WordPress platforms.

Identifying the Vulnerabilities

The vulnerabilities in question, labeled CVE-2026-61979 and CVE-2026-15981, pose a significant threat. The MiniOrange SAML 2.0 SSO plugin, which is installed on over 10,000 WordPress sites, is the focus. Although the free version’s usage is documented, data on the premium and enterprise editions remains unclear.

DigitalOcean, in collaboration with security experts at Patchstack, identified these vulnerabilities as critical authentication bypasses. These can allow unauthorized access to any WordPress account, potentially granting hackers administrative privileges.

Exploitation and Concerns

Patchstack describes the hacker attempts as opportunistic, rather than a targeted attack. The primary concern lies in the fact that despite the vulnerabilities being patched, users have not been sufficiently alerted to the risks. The free version’s update is noted as a bug fix in version 5.4.5, without clear emphasis on its security implications.

For premium users, the situation is more complex. The lack of notifications and a separate versioning system complicate the process of confirming that a site is secure. Users are required to manually update their plugins, heightening the risk of exploitation.

Implications for WordPress Users

Patchstack warns that the attackers are indiscriminately targeting sites with the plugin, regardless of the version or edition. This indiscriminate approach underscores the dangers of silent patches, where users remain unaware of potential threats while the attackers exploit unpatched vulnerabilities.

SecurityWeek has reached out to the plugin’s developer for further comments. As the situation develops, updates will be provided to keep the community informed.

With the growing number of WordPress sites facing potential security breaches, it is crucial for site administrators to ensure their plugins are up-to-date and to remain vigilant about emerging threats.

Security Week News Tags:authentication bypass, CVE-2026-15981, CVE-2026-61979, Cybersecurity, DigitalOcean, MiniOrange plugin, Patchstack, plugin update, website protection, WordPress security

Post navigation

Previous Post: NVIDIA NemoClaw Vulnerability Risks AI Model Security
Next Post: AI Agents Compromise Asian Government Systems, Steal Data

Related Posts

Five Cybersecurity Predictions for 2026: Identity, AI, and the Collapse of Perimeter Thinking Five Cybersecurity Predictions for 2026: Identity, AI, and the Collapse of Perimeter Thinking Security Week News
Depthfirst Raises  Million for Vulnerability Management Depthfirst Raises $40 Million for Vulnerability Management Security Week News
Adobe Issues Out-of-Band Patches for AEM Forms Vulnerabilities With Public PoC Adobe Issues Out-of-Band Patches for AEM Forms Vulnerabilities With Public PoC Security Week News
SolarWinds Patches Critical Web Help Desk Vulnerabilities SolarWinds Patches Critical Web Help Desk Vulnerabilities Security Week News
Anthropic Pauses AI Models Amid U.S. Export Controls Anthropic Pauses AI Models Amid U.S. Export Controls Security Week News
HPE Addresses Critical AOS-CX Security Flaws HPE Addresses Critical AOS-CX Security Flaws Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Autonomous AI Agents Pose New Cybersecurity Threats
  • OpenAI Dismisses Researchers Amid AI Safety Concerns
  • GitHub Action Flaw Exposes Thousands to Credential Theft
  • Critical AnyDesk Linux Vulnerability Allows Remote Code Execution
  • Exploits Target AhsayCBS to Deploy Crypto Miners

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Autonomous AI Agents Pose New Cybersecurity Threats
  • OpenAI Dismisses Researchers Amid AI Safety Concerns
  • GitHub Action Flaw Exposes Thousands to Credential Theft
  • Critical AnyDesk Linux Vulnerability Allows Remote Code Execution
  • Exploits Target AhsayCBS to Deploy Crypto Miners

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark