miniOrange SAML plugin auth bypass lets attackers log in as admins
Source headline: Hackers target WordPress sites in miniOrange auth bypass attacks
Intelligence Summary
Attackers are targeting WordPress sites using authentication bypass flaws in the miniOrange SAML 2.0 Single Sign On plugin. The weaknesses can be abused to forge SAML responses. Successful abuse allows attackers to log in as administrators. The issue affects the miniOrange plugin’s SAML-based authentication flow. If you use this plugin, review your setup and apply available fixes or mitigations immediately.
Recommended Action
Confirm whether the affected technology is in use in your environment before deciding on remediation. Until then, watch authentication and outbound traffic logs for the indicators described in the source. This signal rests on a single report, so corroborate it before acting on anything irreversible.