Attackers Exploit miniOrange SAML Flaws to Gain WordPress Admin Access
Threat actors are actively exploiting two critical authentication bypass vulnerabilities in the Xecurify miniOrange SAML 2.0 Single Sign On plugin for WordPress.…
Threat actors are actively exploiting two critical authentication bypass vulnerabilities in the Xecurify miniOrange SAML 2.0 Single Sign On plugin for WordPress.…
CVE-2026-61979 is an unauthenticated privilege escalation vulnerability in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. It stems from signature…
CVE-2026-15981 is a critical authentication bypass vulnerability in the miniOrange SAML 2.0 Single Sign On plugin. It allows unauthenticated attackers to log…
Company behind the Elementor and Elementor Pro WordPress plugins, which were affected by a critical file upload vulnerability (CVE-2026-32475).
Cybersecurity researchers have disclosed a critical vulnerability in the Elementor Pro WordPress plugin that could allow unauthenticated attackers to upload PHP files…
A large-scale operation turning thousands of compromised WordPress websites into infrastructure for malware delivery, C2 communications, and stolen data storage.
Cybersecurity researchers have uncovered a global cybercrime operation dubbed 'StopAndProtect' that abuses nearly 2,000 hacked WordPress websites to distribute malware, steal data,…
A critical vulnerability has been disclosed in the Forminator Forms WordPress plugin, which has over 600,000 active installations. Tracked as CVE-2026-15748 and…
High-severity WordPress core vulnerability enabling remote code execution via malicious Postscript file upload by Author-level users. Affects versions 4.7 to 7.0. Patched…
The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched Microsoft Windows…