Skip to main content
CyberSingle-sourceMediumDeveloping
5.5

Active exploitation of critical authentication bypass vulnerabilities in miniOrange SAML plugin for WordPress

Threat actors are actively exploiting two critical vulnerabilities in the miniOrange SAML 2.0 SSO plugin, allowing unauthorized administrative access via forged SAML responses. The scope of successful compromises remains unquantified, posing a significant risk to organizations relying on the plugin for identity management.

BleepingComputerabout 2 hours agoengCredibility 59%View source

Score Breakdown

Mosaic Score5.5
Confidence0.9
Significance0.5
Source credibility0.6
Source

Related signals

8 found