Login
← All news

Hackers target WordPress sites in miniOrange auth bypass attacks

BleepingComputer by Bill Toulas Security WordPress
illustration

Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators.

Read the full story on BleepingComputer https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-in-miniorange-auth-bypass-attacks/
Most WordPress sites are compromised through something ordinary: an unpatched plugin, an abandoned theme, an account without two-factor. If you would rather updates and backups simply happened, CrockyHost hosting does them for you.