One slug, seven editions: the miniOrange SAML SSO bug that let anyone log in as your WordPress admin
DigitalOcean researchers reported a critical authentication flaw in miniOrange SAML SSO WordPress plugins, allowing login as WordPress admin across seven editions.
The DigitalOcean security team identified a critical flaw in miniOrange's SAML SSO WordPress plugins that allowed an attacker to authenticate as a WordPress administrator. Patchstack notes the issue spans seven editions of the plugin, all sharing a common slug. The write-up covers root cause analysis by DigitalOcean and vendor follow-up coordinated jointly with Patchstack; no specific CVE id is cited in the text.
- Critical bug allowed login as WordPress admin
- Affected seven editions of the miniOrange SAML SSO plugin
- Discovered by the DigitalOcean security team
- Root cause analysis and vendor follow-up coordinated with Patchstack
Reported by the DigitalOcean security team, with root cause analysis by DigitalOcean, coverage and vendor follow-up handled jointly with Patchstack. Most vulnerability write-ups are about the bug. This is primarily about everything around the bug, where the actual risk ended up living. The DigitalOcean security team identified a critical gap the hard way, based on […]
This source does not provide full text. Read it at patchstack.com.