60
45
30
30
60
30
60
30
30
30
30
60
35
60
60
60
60
55
35
60
60
30
60
30
60
30
30
One slug, seven editions: the miniOrange SAML SSO bug that let anyone log in as your WordPress admin
DigitalOcean researchers reported a critical authentication flaw in miniOrange SAML SSO WordPress plugins, allowing login as WordPress admin across seven editions.
The DigitalOcean security team identified a critical flaw in miniOrange's SAML SSO WordPress plugins that allowed an attacker to authenticate as a WordPress administrator. Patchstack notes the issue spans seven editions of the plugin, all sharing a common slug. The write-up covers root cause analysis by DigitalOcean and vendor follow-up coordinated jointly with Patchstack; no specific CVE id is cited in the text.
58
60
60
30
57
55
30
60
30
57
57
60
60