CRITICALVulnerability
Global

Hackers target WordPress sites in miniOrange auth bypass attacks

·Source: BleepingComputer

Updated:

Executive Summary

Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. [...]

Analysis

Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. [...]
Source Attribution

Originally published by BleepingComputer on Aug 24, 2026.

Related Threats