Back to all news
Security

Hackers target WordPress sites in miniOrange auth bypass attacks

BleepingComputer·August 24, 2026·1 min read
Hackers target WordPress sites in miniOrange auth bypass attacks

Hackers are actively exploiting two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress, which can allow attackers to forge SAML responses and log in as administrators. The warnings highlight the urgent need for WordPress site administrators to patch the plugin immediately to prevent unauthorized access.

Read at BleepingComputer
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store