Hackers target WordPress sites in miniOrange auth bypass attacks
Cybersecurity researchers have discovered a pair of critical vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, allowing hackers to forge SAML responses and log in as administrators without needing valid credentials. This exploit has been observed in exploitation attempts targeting several thousand websites running the affected plugins. The miniOrange SAML SSO … Read more