Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 20 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user including administrators The vulnerabilities as disclosed by Patchstack are listed below CVE202661979 CVSS score 81 An unauthenticated privilege escalation