
Attackers are forging SAML responses to bypass WordPress authentication in miniOrange SSO plugin exploits. TRC analysis shows threat actors gained admin access through CVE-2024-61979 and CVE-2024-15981, then escalated privileges within compromised CMS environments. Runtime segmentation helps contain post-compromise lateral movement. #CloudSecurity 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/hackers-target-wordpress-sites-miniorange-auth-bypass-attacks-cve-2026-61979-cve-2026-15981
Post summary
The post reports attackers actively exploiting CVE‑2024‑61979 and CVE‑2024‑15981 to gain admin access on WordPress sites via forging SAML responses, highlighting a real‑world containment scenario.
