← Back to Feed

Hackers target WordPress sites in miniOrange auth bypass attacks

August 24, 2026 · BleepingComputer · Severity: CRITICAL

Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators.

Key Takeaways

  • Attackers exploit miniOrange SAML 2.0 plugin flaws to forge SAML responses and gain admin access.
  • The vulnerabilities allow unauthenticated attackers to bypass authentication and log in as any WordPress user.
  • WordPress site administrators must urgently patch the miniOrange plugin to prevent full site compromise.
☕ Buy a Coffee