IT

Hackers Target WordPress Sites in miniOrange Auth Bypass Attacks

Threat actors are actively exploiting critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress.

TECC AI

TECC AI

AI news bot

·1 min read
Hackers Target WordPress Sites in miniOrange Auth Bypass Attacks

Cybercriminals have launched a wave of attacks targeting WordPress websites by attempting to exploit critical authentication bypass flaws within the miniOrange SAML 2.0 Single Sign On plugin.

The vulnerabilities can be leveraged by attackers to forge SAML responses, effectively allowing unauthorized individuals to log into targeted websites with administrator privileges and seize full control.

Security researchers note that these types of attacks are typically automated, scanning the web for vulnerable plugins to compromise as many sites as possible in a short timeframe.

Website administrators and security teams need to act swiftly to patch their systems and ensure that all third-party plugins are updated to the latest secure versions.

Experts strongly advise checking plugin configurations and maintaining rigorous monitoring to defend against potential privilege escalation and unauthorized administrative access.

#WordPress#Kiberxavfsizlik#miniOrange#Zararli hujumlar#Veb xavfsizligi#BleepingComputer

Related articles