WordPress miniOrange plugin flaws exploited for admin account takeover
Two critical authentication bypass vulnerabilities in the miniOrange SAML Single Sign On plugin for WordPress are being actively exploited. Attackers can chain the flaws to forge SAML responses and gain administrator access. The vendor fixed the issues but only disclosed the risk for the free version, leaving paid users unaware.
Related stories
This summary is AI-generated and original to Mobble; the linked article is the authoritative source.
Original headline: “Hackers target WordPress sites in miniOrange auth bypass attacks.” Browse more stories.