WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities
CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin. WordPress Websites Targeted via.
By Dillip Chowdary • Aug 25, 2026 • Source: SecurityWeek
What happened
SecurityWeek reports: WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities. CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin. The post WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities appeared first on SecurityWeek .

Advertisement
Tech Pulse Daily
Get tomorrow's pulse first
Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.
How it works
Read the original coverage at SecurityWeek via the source link above for the complete details and primary quotes.
Who is affected
Cross-check release notes and official docs before changing production systems based on early reporting.
Developer Action Items
- ☐ Diff the official changelog for WordPress Websites Targeted MiniOrange 2.0 before you bump — APIs, defaults, and removed flags only.
- ☐ Install through the vendor's documented channel in staging; keep a one-command rollback and time-box the canary.
- ☐ Grep your repo for old flag names, lockfile pins, and plugin versions that the notes mark as breaking.
- ☐ Prefer the first patch cut over the day-zero tag unless you have a reason to be on the leading edge.
- ☐ If SecurityWeek did not name a region, plan, or SKU, screenshot the official availability line before you promise it to users.
Advertisement
🔎 More interesting news
- Apple launches next-gen Apple Silicon chips: M6 and M5 Ultra
- Alice Raises $140M to Expand AI Model Defenses and Enterprise Guardrails
- ClaudeGate – Use OpenRouter Models (0x Alpha, DeepSeek) in Claude Code CLI
- Apple releases new Magic Keyboards with one notable change
- Today's full Tech Pulse briefing →