Hackers target WordPress sites in miniOrange auth bypass attacks

Summary

Hackers are actively exploiting two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. These vulnerabilities allow attackers to forge SAML responses and gain administrator access to affected websites.

IFF Assessment

FOE

The vulnerabilities allow attackers to bypass authentication and gain administrative control, which is detrimental to defenders.

Severity

9.8 Critical (AI Estimated)

The CVSS score is estimated to be high (9.8) due to the critical nature of authentication bypass, the ability to gain administrator privileges, and the ease of exploiting SAML response forging. The attack vector is network, and the impact on confidentiality, integrity, and availability is high.

Defender Context

Defenders should prioritize patching or updating the miniOrange SAML 2.0 Single Sign On plugin for WordPress to mitigate these critical authentication bypass vulnerabilities. Continuous monitoring for unauthorized administrative access and suspicious SAML activity is crucial to detect and respond to potential compromises.

Read Full Story →