
Hackers Exploit Critical Authentication Bypass Flaws in miniOrange WordPress SSO Plugin
SecurityWordPressVulnerabilityAuthenticationBypassHackingSAMLSSODataBreach
Hackers are actively exploiting two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On (SSO) plugin for WordPress, allowing attackers to forge SAML responses and gain administrator-level access. The flaws enable unauthorized logins without valid credentials by manipulating authentication mechanisms. No specific CVE IDs, dates, or affected version ranges were disclosed in the reported details. The attacks target WordPress sites using the vulnerable plugin, though the scale of exploitation remains unquantified. The impact includes potential full site compromise, data theft, or further malicious activity under elevated privileges.