Hackers target WordPress sites in miniOrange auth bypass attacks

Read full story on BleepingComputer
Share
Hackers target WordPress sites in miniOrange auth bypass attacks
AI disclosure

Summary

Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. [...]

Original reporting

Open original source
Read full article on BleepingComputer

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.