Skip to main content
Back to Newswire
Security

Attackers target miniOrange WordPress SAML flaws for administrator access

Attackers target miniOrange WordPress SAML flaws for administrator access Image: Primary
Attackers are attempting to exploit two critical authentication-bypass flaws in miniOrange's WordPress SAML SSO plugin, which can be chained to forge SAML responses and obtain administrator access, BleepingComputer reports. Patchstack observed exploitation attempts and scanning from six IP addresses across Europe, Africa and the United States, after an anomalous administrator session tied to the Standard edition was blocked on Aug. 16. The flaws were fixed in July, but paid editions did not receive dashboard update warnings, according to the report.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire