<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[🔴 Critical: Hackers target WordPress sites in miniOrange auth bypass attacks]]></title><description><![CDATA[<p dir="auto">Attackers are actively targeting WordPress sites running the <strong>miniOrange SAML 2.0 Single Sign On</strong> plugin, attempting to exploit two critical authentication bypass flaws. Successful exploitation would allow an unauthenticated attacker to forge SAML responses and gain administrative access to the affected site.</p>
<p dir="auto">The vulnerabilities stem from improper handling of SAML responses and a lack of proper signature verification in the plugin’s login flow. If exploited, an attacker could effectively bypass the authentication process, granting them full control over the WordPress installation without needing valid credentials. This level of access enables further compromise, such as injecting malicious scripts, altering site content, or exfiltrating data.</p>
<ul>
<li>The two flaws affect the <em>miniOrange SAML 2.0 Single Sign On</em> plugin.</li>
<li>The issues are specifically related to authentication bypass and SAML response forging.</li>
<li>No specific CVE identifiers were disclosed in the provided report.</li>
<li>Sites using this plugin should immediately verify they are running the latest patched version.</li>
</ul>
<p dir="auto">Given the critical nature of these flaws, administrators are urged to:</p>
<ul>
<li>Apply any available plugin updates immediately.</li>
<li>Review recent user account activity for unexpected administrator-level changes.</li>
<li>Audit login logs for unusual or foreign requests, particularly those containing SAML-related parameters.</li>
</ul>
<p dir="auto">These attacks highlight the persistent risk posed by authentication plugins, which are high-value targets because they guard access to the entire content management system. Even with no active exploit code publicly available, the observed attack attempts indicate that threat actors are actively scanning for vulnerable installations.</p>
<p dir="auto">Source: <a href="https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-in-miniorange-auth-bypass-attacks" target="_blank" rel="noopener noreferrer nofollow ugc">Unknown</a></p>
<p dir="auto">Is your WordPress environment running any SAML-based SSO plugins, and have you checked your current plugin version against this advisory?</p>
]]></description><link>https://xploitlk.com/topic/87/critical-hackers-target-wordpress-sites-in-miniorange-auth-bypass-attacks</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 13:28:16 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/87.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 24 Aug 2026 20:30:20 GMT</pubDate><ttl>60</ttl></channel></rss>