Home / Aug 25, 2026 / Story
0
#9 BleepingComputer general August 24, 2026 at 19:26 UTC

Hackers target WordPress sites in miniOrange auth bypass attacks

By Bill Toulas

AI Summary

Active exploitation attempts are underway against two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, which can be abused to forge SAML responses and authenticate as administrators without credentials. WordPress site administrators running this plugin should apply patches immediately, as SAML auth bypass flaws provide direct privileged access to affected installations.

Relevance score: 74.0/100

# More from August 25