{
  "id": 3231535,
  "title": "Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access",
  "url": "https://urgent.news/2026/08/25/attackers-target-miniorange-saml-flaws-that-can-grant-wordpress-admin",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-25T08:34:07.000Z",
  "source": {
    "name": "The Hacker News",
    "slug": "the-hacker-news",
    "url": "https://thehackernews.com/2026/08/attackers-target-miniorange-saml-flaws.html"
  },
  "original_language": "en",
  "account": null,
  "summary": "Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators. The vulnerabilities, as disclosed by Patchstack, are listed below - CVE-2026-61979 (CVSS score: 8.1) - An unauthenticated privilege escalation",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}