Attackers are actively exploiting two critical authentication bypass vulnerabilities in the Xecurify miniOrange SAML 2.0 Single Sign-On plugin for WordPress. The flaws allow unauthenticated threat actors to gain administrator access to affected WordPress installations.
Patchstack disclosed the vulnerabilities, with CVE-2026-61979 receiving a CVSS score of 8.1. This rating reflects a high-severity unauthenticated privilege escalation flaw. The vulnerability permits attackers to bypass authentication entirely and sign in as any WordPress user, including site administrators, without requiring valid credentials or knowing passwords.
SAML 2.0 (Security Assertion Markup Language) plugins handle federated authentication on WordPress sites. Organizations use miniOrange's implementation to enable single sign-on across multiple systems and reduce password management overhead. The compromised authentication logic in this plugin means that integrations relying on miniOrange's SAML handling become direct attack surfaces for account takeover.
The attack vector requires no interaction from victims. Threat actors can remotely trigger the privilege escalation and establish administrative access within seconds. Once an attacker obtains administrator privileges on a WordPress site, the damage scope expands dramatically. They gain ability to install malicious plugins, modify core site files, exfiltrate databases containing customer data, inject malware into website content, create persistent backdoors, and pivot to hosting infrastructure.
WordPress powers approximately 43 percent of all websites globally, making it a priority target for threat actors. Authentication plugins represent high-value attack surfaces because compromising them affects entire ecosystems of connected organizations relying on centralized identity management.
The miniOrange SAML plugin serves enterprises and government agencies that need enterprise-grade authentication workflows. These organizations typically handle sensitive data, financial records, and confidential communications. A successful administrative compromise exposes not just the WordPress site itself but potentially connected systems that rely on the compromised instance for authentication.
Security teams managing WordPress deployments should treat this vulnerability with urgency. The combination of unauthenticated access and administrative privilege escalation creates a critical risk requiring immediate remediation. Organizations running miniOrange SAML 2.0 should verify their plugin version and apply patches immediately upon availability.
Active exploitation attempts indicate that threat actors have already weaponized this vulnerability in the wild. Delaying patching increases the probability of compromise. Security teams should also review web application firewalls and intrusion detection rules to detect exploitation attempts, monitor administrator account creation and login events for anomalies, and audit plugin activity logs for suspicious behavior patterns.
Organizations unable to patch immediately should consider temporarily disabling the plugin until fixes deploy, restricting administrative access to trusted networks only, and implementing multi-factor authentication on all WordPress administrator accounts to add defensive layers against account takeover.
Xecurify needs to release patched versions addressing both CVE-2026-61979 and any related authentication bypass flaws. Security researchers and plugin users should monitor official Xecurify channels and WordPress.org plugin directory for patch announcements.
