PentestingHere
Log in Join
[HIGH] · Self-hosted / private program · Disclosed

Unauthenticated privilege escalation in SAML SP Single Sign On (WordPress) up to 5.4.3

Youssef Eid Youssef Eid CVE-2026-61979 Patchstack 13 Aug 2026

Summary

A privilege escalation in the miniOrange SAML SP Single Sign On plugin for WordPress, versions up to and including 5.4.3. It can be reached without authenticating, and lets an attacker turn a low-privileged account into a higher-privileged one.

Impact

Elevated privileges on a WordPress site are the whole site: with them an attacker can take full control. Patchstack rated this 8.1.

Fix

Patched in 5.4.4.

References

  • CVE-2026-61979
  • Patchstack advisory: patchstack.com/database/wordpress/plugin/miniorange-saml-20-single-sign-on/vulnerability/wordpress-saml-sp-single-sign-on-plugin-5-4-3-privilege-escalation-vulnerability