Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

Summary

Attackers are exploiting two severe vulnerabilities in the Xecurify miniOrange SAML 2.0 Single Sign On plugin for WordPress. These flaws allow unauthenticated attackers to bypass authentication and gain administrative access to WordPress sites.

IFF Assessment

FOE

The vulnerabilities allow attackers to gain unauthorized administrative access to WordPress sites, posing a significant threat to data and system integrity.

Severity

8.1 High

Defender Context

This highlights the critical need for organizations using the miniOrange SAML plugin to promptly apply any available patches or updates. Defenders should monitor for unusual login activity and unauthorized administrative actions on their WordPress instances. Supply chain risks, as seen with third-party plugins, remain a constant concern.

Read Full Story →