Summary
Attackers are exploiting two vulnerabilities in the miniOrange SAML SSO plugin to bypass authentication and gain administrative access to WordPress sites.
Take Action:
If you use the miniOrange SAML 2.0 SSO plugin on WordPress, check your version manually and download the latest release from the miniOrange store right away. The plugin has flaws that are actively exploited. The dashboard won't warn you about updates if you're on a paid edition. If you can't update immediately, deactivate the plugin and review your admin login history for logins from unfamiliar IP addresses, since attackers may already have created or hijacked admin accounts.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (0)