
Attackers are forging SAML responses to bypass WordPress authentication in miniOrange SSO plugin exploits. TRC analysis shows threat actors gained admin access through CVE-2024-61979 and CVE-2024-15981, then escalated privileges within compromised CMS environments. Runtime segmentation helps contain post-compromise lateral movement. #CloudSecurity 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/hackers-target-wordpress-sites-miniorange-auth-bypass-attacks-cve-2026-61979-cve-2026-15981
Post summary
The message reports that attackers are forging SAML responses to exploit CVE‑2024‑61979 and CVE‑2024‑15981 for admin access on WordPress sites using the miniOrange SSO plugin, demonstrating active malicious use of the vulnerabilities.
