CVE-2026-61979 is an unauthenticated privilege escalation vulnerability in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. It stems from signature algorithm confusion, allowing attackers to bypass authentication and potentially gain admin access. The issue is fixed in version 17.0.5 of the Standard edition.