Hackers target WordPress sites in miniOrange auth bypass attacks

Executive Summary

Hackers are exploiting two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign-On plugin for WordPress. The flaws allow attackers to forge SAML responses and log in as administrators, potentially compromising sites. The vulnerabilities affect all WordPress installations using the plugin and have been publicly disclosed by security researchers. Site owners are urged to update the plugin or apply vendor patches immediately.


Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-08-24T19:26:32+00:00 - Category: threat-intel

Original Description: Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. [...]

"The real measure of your wealth is how much youd be worth if you lost all your money."

— Unknown
Source: Bleeping Computer