The Hacker NewsWednesday · August 26, 2026FREE

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

wordpresssamlsecurityexploit

The Hacker News reported that attackers are actively targeting security flaws in the miniOrange SAML plugin for WordPress. These flaws could potentially grant attackers administrative access to affected WordPress sites. The report does not specify the exact vulnerabilities, their severity, or the versions affected, but it indicates that exploitation is occurring in the wild. The source also does not provide details on the number of affected installations or the timeline of the attacks. The miniOrange SAML plugin is used for integrating WordPress with SAML-based single sign-on (SSO) systems, and a compromise could allow attackers to take full control of a site. The report does not include any mitigation steps or patches, and it does not mention whether miniOrange has released a fix. The article serves as a warning to WordPress administrators using the plugin to be aware of the active exploitation.

// why it matters

Active exploitation of miniOrange SAML flaws could lead to full WordPress admin takeover, compromising site integrity.

Sources

Primary · The Hacker News
▸ Read original at thehackernews.com

Like this? Get the next digest.