Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
Summary
Attackers are exploiting two severe vulnerabilities in the Xecurify miniOrange SAML 2.0 Single Sign On plugin for WordPress. These flaws allow unauthenticated attackers to bypass authentication and gain administrative access to WordPress sites.
IFF Assessment
FOE
The vulnerabilities allow attackers to gain unauthorized administrative access to WordPress sites, posing a significant threat to data and system integrity.
Severity
8.1
High
Defender Context
This highlights the critical need for organizations using the miniOrange SAML plugin to promptly apply any available patches or updates. Defenders should monitor for unusual login activity and unauthorized administrative actions on their WordPress instances. Supply chain risks, as seen with third-party plugins, remain a constant concern.