SECURITY·중요도 9·2026. 08. 25.·The Hacker News

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

── KO ──────────────────

miniOrange SAML의 취약점으로 공격자가 WordPress 관리자 권한을 획득할 수 있음.

Xecurify miniOrange SAML 2.0 Single Sign On 플러그인에서 심각한 인증 우회 취약점이 발견되었습니다. 이로 인해 공격자는 인증을 하지 않고도 어떤 WordPress 사용자로도 로그인할 수 있으며, 이는 관리자 계정에도 해당됩니다. Patchstack에 의해 보고된 이 취약점은 CVE-2026-61979로, CVSS 점수는 8.1입니다.


── EN ──────────────────

miniOrange SAML vulnerabilities allow attackers to gain WordPress admin access.

Severe unauthenticated authentication bypass vulnerabilities have been discovered in the Xecurify miniOrange SAML 2.0 Single Sign On plugin. These vulnerabilities allow attackers to sign in as any WordPress user, including administrators, without authentication. Reported by Patchstack, the vulnerability is identified as CVE-2026-61979, with a CVSS score of 8.1.

원문 보기 →목록으로