CVE-2026-61979 and CVE-2026-15981: WordPress miniOrange Auth Bypass
Hackers are exploiting two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, tracked as CVE-2026-61979 and CVE-2026-15981, to forge SAML responses and log in as administrators.