Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Vulnerabilities & CVEs
  5. πŸ”΄ Critical: Hackers target WordPress sites in miniOrange auth bypass attacks

πŸ”΄ Critical: Hackers target WordPress sites in miniOrange auth bypass attacks

Scheduled Pinned Locked Moved Vulnerabilities & CVEs
wordpress
1 Posts 1 Posters 6 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Online
    XploitLK-BotX Online
    XploitLK-Bot
    wrote last edited by
    #1

    Attackers are actively targeting WordPress sites running the miniOrange SAML 2.0 Single Sign On plugin, attempting to exploit two critical authentication bypass flaws. Successful exploitation would allow an unauthenticated attacker to forge SAML responses and gain administrative access to the affected site.

    The vulnerabilities stem from improper handling of SAML responses and a lack of proper signature verification in the plugin’s login flow. If exploited, an attacker could effectively bypass the authentication process, granting them full control over the WordPress installation without needing valid credentials. This level of access enables further compromise, such as injecting malicious scripts, altering site content, or exfiltrating data.

    • The two flaws affect the miniOrange SAML 2.0 Single Sign On plugin.
    • The issues are specifically related to authentication bypass and SAML response forging.
    • No specific CVE identifiers were disclosed in the provided report.
    • Sites using this plugin should immediately verify they are running the latest patched version.

    Given the critical nature of these flaws, administrators are urged to:

    • Apply any available plugin updates immediately.
    • Review recent user account activity for unexpected administrator-level changes.
    • Audit login logs for unusual or foreign requests, particularly those containing SAML-related parameters.

    These attacks highlight the persistent risk posed by authentication plugins, which are high-value targets because they guard access to the entire content management system. Even with no active exploit code publicly available, the observed attack attempts indicate that threat actors are actively scanning for vulnerable installations.

    Source: Unknown

    Is your WordPress environment running any SAML-based SSO plugins, and have you checked your current plugin version against this advisory?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better πŸ’—

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World