# Attackers target miniOrange WordPress SAML flaws for administrator access

_Monday, August 24, 2026 at 3:26 PM EDT · Security · Latest · Tier 2 — Notable_

![Attackers target miniOrange WordPress SAML flaws for administrator access — Primary](https://www.bleepstatic.com/content/hl-images/2026/08/24/miniorange.jpg)

Attackers are attempting to exploit two critical authentication-bypass flaws in miniOrange's WordPress SAML SSO plugin, which can be chained to forge SAML responses and obtain administrator access, BleepingComputer reports.

Patchstack observed exploitation attempts and scanning from six IP addresses across Europe, Africa and the United States, after an anomalous administrator session tied to the Standard edition was blocked on Aug. 16. The flaws were fixed in July, but paid editions did not receive dashboard update warnings, according to the report.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-in-miniorange-auth-bypass-attacks/)

---
Canonical: https://techandbusiness.org/newswire/MZoCRlKAGZj64ZwTvMhkuH
Retrieved: 2026-08-24T22:02:30.259Z
Publisher: Tech & Business (techandbusiness.org)
