CVE-2026-61979 carries a CVSS 3.1 base score of 8.1 against MiniOrange’s SAML SP Single Sign On WordPress plugin. NVD classifies it as CWE-266 (Incorrect Privilege Assignment) and states the flaw affects versions up to and including 5.4.3. VulnCheck’s KEV feed reports the CVE as exploited, dated August 21, 2026.
That exploitation report is single-sourced. CISA has not added CVE-2026-61979 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. No Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
What the flaw is
NVD’s description for this CVE is brief: “Unauthenticated Privilege Escalation in SAML SP Single Sign On <= 5.4.3 versions.” NVD does not name the specific SAML assertion-handling function or code path responsible; Patchstack’s vulnerability database entry, cited from NVD’s own reference list, is the only additional public source we currently have, and our source data does not carry deeper mechanism detail from it.
We report NVD’s classification as stated rather than speculating about the missing technical detail behind a description this brief.
Evidence and confidence
- Medium confidence — the CVSS 8.1 score, the vector (
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H), and the CWE-266 classification, which trace to NVD alone in our current ingestion, with a corroborating listing from Patchstack. The exploitation report traces to VulnCheck KEV alone. - Low-to-moderate exploitation probability — FIRST’s EPSS model scores this CVE at 0.00278, a 20.3rd percentile score as of our ingestion.
No field is in conflict between our two sources.
Why this matters
A fully unauthenticated privilege escalation in a Single Sign-On plugin is a particularly high-stakes combination: SSO plugins exist specifically to broker identity and authorization decisions, so a flaw that lets an unauthenticated attacker escalate privileges through the very component responsible for authentication undermines the trust boundary the plugin is meant to enforce. Any WordPress site using this plugin for SAML-based sign-on should treat this as a priority patch regardless of the sparse public technical detail currently available.
Frequently Asked Questions
What is CVE-2026-61979? A CVSS 8.1 incorrect privilege assignment vulnerability (CWE-266) in MiniOrange’s SAML SP Single Sign On WordPress plugin, affecting versions up to and including 5.4.3, allowing unauthenticated attackers to escalate privileges.
Is CVE-2026-61979 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated August 21, 2026. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.
Do I need an account to exploit this?
No. Both NVD’s description and the CVSS vector’s PR:N confirm this is exploitable without any authentication.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.
Is a fixed version available? Our source data does not carry a specific fixed-version number beyond NVD’s statement that versions “up to, and including, 5.4.3” are affected. Consult the plugin vendor directly for the current patched release.
Severity, vector, and weakness classification sourced from the National Vulnerability Database record for CVE-2026-61979, corroborated by Patchstack’s vulnerability database entry. Exploitation status and the August 21, 2026 catalog date reported by VulnCheck KEV. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.