Authentication Bypass
-
Attackers exploit miniOrange SAML SSO plugin vulnerabilities in WordPress
A silent patching oversight leaves paid versions of the miniOrange SAML 2.0 Single Sign On plugin vulnerable to authentication bypasses that grant administrative access.