Close Menu
NCIJ Network NCIJ Network
    What's Hot

    LACMA data breach last year exposed social security and medical data

    August 25, 2026

    Bitcoin’s 7 million coin quantum problem just reached the US Treasury

    August 25, 2026

    Depression may shut down the brain’s ability to make new neurons

    August 25, 2026
    Facebook X (Twitter) Instagram
    Trending
    • LACMA data breach last year exposed social security and medical data
    • Bitcoin’s 7 million coin quantum problem just reached the US Treasury
    • Depression may shut down the brain’s ability to make new neurons
    • Indonesia charges 72 over fires as haze chokes Borneo and Sumatra
    • Elon Musk won’t face criminal charges for offering voters $1 million checks during 2025 Supreme Court election
    • China Races Ahead in Robotics as U.S. Tightens Restrictions
    • Did Trump say US was ‘dumb’ country led by ‘very stupid person’ one year ago?
    • U.S. ‘Economic D-Day’ Targets More Than Just Iranian Oil
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, August 25
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 25, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Threat actors have been attempting to hack WordPress websites by exploiting two recently patched vulnerabilities affecting a MiniOrange plugin.

    The two vulnerabilities are CVE-2026-61979 and CVE-2026-15981, and they affect the MiniOrange SAML 2.0 Single Sign-On (SSO) plugin, which enables SSO for WordPress websites. 

    The free edition of the plugin is installed on more than 10,000 WordPress sites, but there are also several paid and enterprise versions for which usage statistics are not available. 

    According to an analysis conducted by DigitalOcean and security firm Patchstack, the vulnerabilities are critical authentication bypasses that can be exploited to log in as any WordPress user, including administrators. 

    Threat actors have been attempting to exploit CVE-2026-61979 and CVE-2026-15981 in what Patchstack described as opportunistic attacks rather than a targeted campaign. 

    The problem is that while all affected versions of the MiniOrange SAML 2.0 SSO plugin have been patched, the developer has not warned users about the potential risks. Only the free edition has an advisory that mentions the fix in version 5.4.5, but it’s listed as a bugfix rather than a security patch. 

    Advertisement. Scroll to continue reading.

    In the case of the paid editions, users have not been notified and a different versioning system makes it difficult to tell whether a website is patched; users have to manually update the plugin.

    “Whoever is running this appears to be throwing the exploit at every site with the plugin installed without checking which edition or version is behind it,” Patchstack warned. “This is exactly the behavior that makes the silent-patch situation dangerous. The attacker does not need to know which edition you run, you do.”

    SecurityWeek has reached out to the developer for comment and will update this article if it responds.

    Related: 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw

    Related: WordPress 7.0.4 Patches Remote Code Execution Vulnerability

    Related: WP2Shell WordPress Vulnerabilities Exploited in the Wild

    miniOrange Plugin targeted Vulnerabilities websites WordPress
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    LACMA data breach last year exposed social security and medical data

    WhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security Update

    Introducing the Admin plugin for ChatGPT Work and Codex

    AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes

    U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

    Alice Raises $140M to Expand AI Model Defenses and Enterprise Guardrails

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    LACMA data breach last year exposed social security and medical data

    August 25, 2026

    Bitcoin’s 7 million coin quantum problem just reached the US Treasury

    August 25, 2026

    Depression may shut down the brain’s ability to make new neurons

    August 25, 2026

    Indonesia charges 72 over fires as haze chokes Borneo and Sumatra

    August 25, 2026
    Latest Posts

    Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates

    July 29, 2026

    Inside the rogue ChatGPT hack of Hugging Face

    July 29, 2026

    ECB wage tracker at 2.7% in Q1 2027, indicating stable negotiated wage pressures

    July 29, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    LACMA data breach last year exposed social security and medical data

    August 25, 2026

    Bitcoin’s 7 million coin quantum problem just reached the US Treasury

    August 25, 2026

    Depression may shut down the brain’s ability to make new neurons

    August 25, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.