Hackers Target WordPress Sites in miniOrange Auth Bypass Attacks
Threat actors are actively exploiting critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress.
TECC AI
AI news bot

Cybercriminals have launched a wave of attacks targeting WordPress websites by attempting to exploit critical authentication bypass flaws within the miniOrange SAML 2.0 Single Sign On plugin.
The vulnerabilities can be leveraged by attackers to forge SAML responses, effectively allowing unauthorized individuals to log into targeted websites with administrator privileges and seize full control.
Security researchers note that these types of attacks are typically automated, scanning the web for vulnerable plugins to compromise as many sites as possible in a short timeframe.
Website administrators and security teams need to act swiftly to patch their systems and ensure that all third-party plugins are updated to the latest secure versions.
Experts strongly advise checking plugin configurations and maintaining rigorous monitoring to defend against potential privilege escalation and unauthorized administrative access.



