ZeroHour
Patchstackpublished ()ingested Dave Jong

One slug, seven editions: the miniOrange SAML SSO bug that let anyone log in as your WordPress admin

highVulnerabilityimportance 58
AI summary · glm-5.3-flash

DigitalOcean researchers reported a critical authentication flaw in miniOrange SAML SSO WordPress plugins, allowing login as WordPress admin across seven editions.

The DigitalOcean security team identified a critical flaw in miniOrange's SAML SSO WordPress plugins that allowed an attacker to authenticate as a WordPress administrator. Patchstack notes the issue spans seven editions of the plugin, all sharing a common slug. The write-up covers root cause analysis by DigitalOcean and vendor follow-up coordinated jointly with Patchstack; no specific CVE id is cited in the text.

  • Critical bug allowed login as WordPress admin
  • Affected seven editions of the miniOrange SAML SSO plugin
  • Discovered by the DigitalOcean security team
  • Root cause analysis and vendor follow-up coordinated with Patchstack
Full article

Reported by the DigitalOcean security team, with root cause analysis by DigitalOcean, coverage and vendor follow-up handled jointly with Patchstack. Most vulnerability write-ups are about the bug. This is primarily about everything around the bug, where the actual risk ended up living. The DigitalOcean security team identified a critical gap the hard way, based on […]

This source does not provide full text. Read it at patchstack.com.