← Back to feed
general Security Affairs

Two CVSS 9.8 Auth Bypasses in miniOrange SAML WordPress Plugin Were Exploited Before Any Database Even Listed the Paid Editions as Vulnerable

Security Affairs • • WordPress

Two CVSS 9.8 miniOrange SAML WordPress plugin auth bypasses were exploited while paid editions never appeared in any vulnerability database.

T1556 2 IOCs
Read the full story Security Affairs →

Related Coverage

general Hackers Use AI Agents and GodPotato Exploit to Gain Windows SYSTEM Privileges GBHackers · Oct 10 general AWS Bedrock AgentCore Flaw Allowed Attackers to Hijack AI Agents Using a Single Prompt GBHackers · Oct 10 general Co-creator of Empire Market dark web marketplace given 40-year sentence The Record · Oct 10