identityvulnerabilityincident-response

Hackers target WordPress sites in miniOrange auth bypass attacks

August 25, 2026

Back to all posts

Source: BleepingComputer

Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators.
identityvulnerabilityincident-response

Concerned about this threat to your business?

We help Canadian SMBs deploy the controls discussed in this article. Free 30-minute assessment — no obligation.

Book a free assessment