Hackers target WordPress sites in miniOrange auth bypass attacks
Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. [...]
What happened
Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. [...]
Why it matters
The incident may affect operational continuity, asset safety or trust around Security. Watch for verified scope and remediation.
Affected entities
View evidence
1 reports · 1 original report · 1 independent
- BleepingComputerPrimary source · Supports · EN · 100%Hackers target WordPress sites in miniOrange auth bypass attacks ↗
Claims
- Hackers target WordPress sites in miniOrange auth bypass attacks Observed
Conflicts
No material conflict detected in the available evidence.
Timeline
- First reported
Market move following event
Market reaction is not yet available for this asset and time window.
Score explanation
Confidence · formula confidence-2.1.0
Source trust84
Independent corroboration51
Primary evidence35
Claim consistency82
Extraction confidence82
Attribution quality90
Impact · formula impact-2.1.0
Event magnitude100
Market relevance74
Entity significance42
Market breadth45
Novelty68
Urgency100
Ranking · formula rank-1.0.0
Confidence factor0.847
Freshness factor0.9998
Breaking bonus8