CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-61979: miniOrange SAML Privilege Escalation

August 25, 2026

CVE-2026-61979 is an unauthenticated privilege escalation vulnerability in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. It stems from signature algorithm confusion, allowing attackers to bypass authentication and potentially gain admin access. The issue is fixed in version 17.0.5 of the Standard edition.