Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit Vulnerabilities in MiniOrange WordPress Plugin

Hackers Exploit Vulnerabilities in MiniOrange WordPress Plugin

Posted on August 25, 2026 By CWS

Hackers are actively seeking to compromise WordPress websites by leveraging two newly addressed vulnerabilities found in a MiniOrange plugin. These flaws affect the SAML 2.0 Single Sign-On (SSO) plugin, a tool that facilitates single sign-on capabilities for WordPress platforms.

Identifying the Vulnerabilities

The vulnerabilities in question, labeled CVE-2026-61979 and CVE-2026-15981, pose a significant threat. The MiniOrange SAML 2.0 SSO plugin, which is installed on over 10,000 WordPress sites, is the focus. Although the free version’s usage is documented, data on the premium and enterprise editions remains unclear.

DigitalOcean, in collaboration with security experts at Patchstack, identified these vulnerabilities as critical authentication bypasses. These can allow unauthorized access to any WordPress account, potentially granting hackers administrative privileges.

Exploitation and Concerns

Patchstack describes the hacker attempts as opportunistic, rather than a targeted attack. The primary concern lies in the fact that despite the vulnerabilities being patched, users have not been sufficiently alerted to the risks. The free version’s update is noted as a bug fix in version 5.4.5, without clear emphasis on its security implications.

For premium users, the situation is more complex. The lack of notifications and a separate versioning system complicate the process of confirming that a site is secure. Users are required to manually update their plugins, heightening the risk of exploitation.

Implications for WordPress Users

Patchstack warns that the attackers are indiscriminately targeting sites with the plugin, regardless of the version or edition. This indiscriminate approach underscores the dangers of silent patches, where users remain unaware of potential threats while the attackers exploit unpatched vulnerabilities.

SecurityWeek has reached out to the plugin’s developer for further comments. As the situation develops, updates will be provided to keep the community informed.

With the growing number of WordPress sites facing potential security breaches, it is crucial for site administrators to ensure their plugins are up-to-date and to remain vigilant about emerging threats.

Security Week News Tags:authentication bypass, CVE-2026-15981, CVE-2026-61979, Cybersecurity, DigitalOcean, MiniOrange plugin, Patchstack, plugin update, website protection, WordPress security

Post navigation

Previous Post: NVIDIA NemoClaw Vulnerability Risks AI Model Security
Next Post: AI Agents Compromise Asian Government Systems, Steal Data

Related Posts

What Can Businesses Do About Ethical Dilemmas Posed by AI? What Can Businesses Do About Ethical Dilemmas Posed by AI? Security Week News
Vodafone Germany Fined  Million Over Privacy, Security Failures Vodafone Germany Fined $51 Million Over Privacy, Security Failures Security Week News
Dataminr to Acquire ThreatConnect for 0 Million Dataminr to Acquire ThreatConnect for $290 Million Security Week News
GeoServer Flaw Exploited in US Federal Agency Hack GeoServer Flaw Exploited in US Federal Agency Hack Security Week News
Daemon Tools Supply Chain Breach Managed, Says Vendor Daemon Tools Supply Chain Breach Managed, Says Vendor Security Week News
Microsoft 365 Direct Send Abused for Phishing Microsoft 365 Direct Send Abused for Phishing Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Linux Foundation to Oversee AI Attestation Standard TRACE
  • Marimo Notebook Flaw Allows MCP Commands in Edit Mode
  • AI Agents Compromise Asian Government Systems, Steal Data
  • Hackers Exploit Vulnerabilities in MiniOrange WordPress Plugin
  • NVIDIA NemoClaw Vulnerability Risks AI Model Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Linux Foundation to Oversee AI Attestation Standard TRACE
  • Marimo Notebook Flaw Allows MCP Commands in Edit Mode
  • AI Agents Compromise Asian Government Systems, Steal Data
  • Hackers Exploit Vulnerabilities in MiniOrange WordPress Plugin
  • NVIDIA NemoClaw Vulnerability Risks AI Model Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark