WordPress Sites Under Attack: Critical Authentication Bypass Flaws in miniOrange Plugin
Threat actors are actively exploiting two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress to…
If you run WordPress with miniOrange SAML 2.0 SSO, immediately check for available patches from the vendor. Consider temporarily disabling the plugin if no official fix is available and alternative mitigations cannot be applied. Monitor access logs for suspicious authentication attempts or unexpected administrative account creation.