Mobble
Technology · Cybersecurity · published 2026-08-24 · via BleepingComputer

WordPress miniOrange plugin flaws exploited for admin account takeover

Two critical authentication bypass vulnerabilities in the miniOrange SAML Single Sign On plugin for WordPress are being actively exploited. Attackers can chain the flaws to forge SAML responses and gain administrator access. The vendor fixed the issues but only disclosed the risk for the free version, leaving paid users unaware.

Read the full article at BleepingComputer →
Related stories
Calix router vulnerability enables unauthenticated remote port mapping · Cybersecurity
This summary is AI-generated and original to Mobble; the linked article is the authoritative source. Original headline: “Hackers target WordPress sites in miniOrange auth bypass attacks.” Browse more stories.