Update the miniOrange SAML 2.0 Single Sign On plugin to the latest patched version immediately. If updating is not immediately possible, disable the plugin to prevent exploitation, noting that this may disrupt SAML-based single sign-on functionality.
Quick answers
What is CVE-2026-61979?
Update the miniOrange SAML 2.0 Single Sign On plugin to the latest patched version immediately. If updating is not immediately possible, disable the plugin to prevent exploitation, noting that this may disrupt SAML-based single sign-on functionality.
How severe is CVE-2026-61979?
high, CVSS 8.6
Is CVE-2026-61979 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-61979 be mitigated?
Update the miniOrange SAML 2.0 Single Sign On plugin to the latest patched version immediately. If updating is not immediately possible, disable the plugin to prevent exploitation, noting that this may disrupt SAML-based single sign-on functionality.
CVSS
8.6
Vendor
Xecurify
Published
Sep 30, 2026 · 08:42
Patch
Unknown / not confirmed
Affected products
miniOrange SAML 2.0 Single Sign On plugin
Mitigation
Update the miniOrange SAML 2.0 Single Sign On plugin to the latest patched version immediately. If updating is not immediately possible, disable the plugin to prevent exploitation, noting that this may disrupt SAML-based single sign-on functionality.
Security researchers have identified two unauthenticated authentication bypass vulnerabilities in the Xecurify miniOrange SAML 2.0 Single Sign On plugin for WordPress. The flaws, tracked as CVE-2026-61979 and CVE-2026-61980, allow attackers to sign in as any WordPress user without valid credentials. Exploitation has been observed in the wild, granting attackers administrative access and potentially leading to full site compromise. Users are urged to update the plugin to the latest patched version immediately.