Security
Attackers target miniOrange WordPress SAML flaws for administrator access
Image: Primary Attackers are attempting to exploit two critical authentication-bypass flaws in miniOrange's WordPress SAML SSO plugin, which can be chained to forge SAML responses and obtain administrator access, BleepingComputer reports.
Patchstack observed exploitation attempts and scanning from six IP addresses across Europe, Africa and the United States, after an anomalous administrator session tied to the Standard edition was blocked on Aug. 16. The flaws were fixed in July, but paid editions did not receive dashboard update warnings, according to the report.
Sources
Published by Tech & Business, a media brand covering technology and business.
This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire