Unauthenticated Privilege Escalation in miniOrange SAML SP Single Sign-On Plugin
CVE-2026-61979
8.1HIGH
What is CVE-2026-61979?
The miniOrange SAML SP Single Sign-On plugin for WordPress, specifically versions up to 5.4.3, is susceptible to an unauthenticated privilege escalation vulnerability. This flaw allows attackers to gain elevated access to the system without proper authentication, potentially compromising sensitive data and functionalities within the application.
Affected Version(s)
SAML SP Single Sign On <= 5.4.3