Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
The Hacker News reported that attackers are actively targeting security flaws in the miniOrange SAML plugin for WordPress. These flaws could potentially grant attackers administrative access to affected WordPress sites. The report does not specify the exact vulnerabilities, their severity, or the versions affected, but it indicates that exploitation is occurring in the wild. The source also does not provide details on the number of affected installations or the timeline of the attacks. The miniOrange SAML plugin is used for integrating WordPress with SAML-based single sign-on (SSO) systems, and a compromise could allow attackers to take full control of a site. The report does not include any mitigation steps or patches, and it does not mention whether miniOrange has released a fix. The article serves as a warning to WordPress administrators using the plugin to be aware of the active exploitation.
Active exploitation of miniOrange SAML flaws could lead to full WordPress admin takeover, compromising site integrity.