#9
BleepingComputer
general
August 24, 2026 at 19:26 UTC
Hackers target WordPress sites in miniOrange auth bypass attacks
By Bill Toulas
AI Summary
Active exploitation attempts are underway against two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, which can be abused to forge SAML responses and authenticate as administrators without credentials. WordPress site administrators running this plugin should apply patches immediately, as SAML auth bypass flaws provide direct privileged access to affected installations.
Relevance score: 74.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →