← Back to feed
general Security Affairs

Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable

Security Affairs WordPress

Two CVSS 9.8 miniOrange SAML WordPress plugin auth bypasses were exploited while paid editions never appeared in any vulnerability database.

T1556 2 IOCs
Read the full story Security Affairs →

Related Coverage

general Critical F5 BIG-IP Vulnerability Exploited as Zero-Day SecurityWeek · Sep 23 general AI-Powered Threats Exploit Digital Trust Through Autonomous Breach Techniques GBHackers · Sep 23 general Autonomous AI Agents Hack Online Retailers for $25 Per Target, Steal 600,000 Credit Cards GBHackers · Sep 23