<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: MiniOrange Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving MiniOrange.</description><lastBuildDate>Sat, 12 Sep 2026 21:30:25 GMT</lastBuildDate><item><title>WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities</title><link>https://securityweek.com/wordpress-websites-targeted-via-miniorange-plugin-vulnerabilities</link><guid isPermaLink="false">cst-5001</guid><description>Two authentication bypass vulnerabilities, CVE-2026-61979 and CVE-2026-15981, affect the MiniOrange SAML 2.0 SSO plugin for WordPress. These flaws enable attackers to circumvent login controls on affected websites. Sources: SecurityWeek.</description><pubDate>Tue, 25 Aug 2026 13:33:12 GMT</pubDate></item><item><title>Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access</title><link>https://thehackernews.com/2026/08/attackers-target-miniorange-saml-flaws.html</link><guid isPermaLink="false">cst-4965</guid><description>Attackers are exploiting two unauthenticated authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. These flaws, including CVE-2026-61979, allow privilege escalation and could enable an attacker to log in as any user, including administrators. Patchstack disclosed the issues, which carry a high severity rating. Sources: The Hacker News.</description><pubDate>Tue, 25 Aug 2026 08:34:07 GMT</pubDate></item><item><title>One slug, seven editions: the miniOrange SAML SSO bug that let anyone log in as your WordPress admin</title><link>https://patchstack.com/articles/one-slug-seven-editions-the-miniorange-saml-sso-bug-that-let-anyone-log-in-as-your-wordpress-admin</link><guid isPermaLink="false">cst-5818</guid><description>The miniOrange SAML 2.0 Single Sign On WordPress plugin contained two critical unauthenticated authentication bypasses (CVE-2026-61979 and CVE-2026-15981) that allowed attackers to forge SAML assertions and gain administrator access. The plugin ships under a single WordPress slug but contains seven independently versioned editions, and public security advisories only covered the free edition, leaving six paid editions silently patched without public documentation. As a result, vulnerability databases incorrectly reported paid-edition installations as unaffected while they remained vulnerable, and affected sites received no update prompts in their WordPress dashboards. Sources: Patchstack.</description><pubDate>Fri, 21 Aug 2026 16:58:22 GMT</pubDate></item></channel></rss>