vulnerability
WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities
High
Summary
Threat actors are actively exploiting two recently patched vulnerabilities within the MiniOrange SAML 2.0 Single Sign-On plugin for WordPress websites. These vulnerabilities allow attackers to bypass authentication and gain access to any WordPress user account, despite the fact that patches are available and the developer hasn't adequately warned users about the risks.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data