Unauthenticated Privilege Escalation in miniOrange SAML SP Single Sign-On Plugin
CVE-2026-61979

8.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
13 August 2026

What is CVE-2026-61979?

The miniOrange SAML SP Single Sign-On plugin for WordPress, specifically versions up to 5.4.3, is susceptible to an unauthenticated privilege escalation vulnerability. This flaw allows attackers to gain elevated access to the system without proper authentication, potentially compromising sensitive data and functionalities within the application.

Affected Version(s)

SAML SP Single Sign On <= 5.4.3

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

sequence_X0 | Patchstack Bug Bounty Program
.