home.social

#miniorange — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #miniorange, aggregated by home.social.

fetched live
  1. Hackers Exploit WordPress Sites in miniOrange Auth Bypass Attacks

    Hackers are actively exploiting WordPress sites using a clever combination of two vulnerabilities, CVE-2026-61979 and CVE-2026-15981, to bypass authentication and gain administrator access. This stealthy attack uses the miniOrange SAML 2.0 Single Sign On plugin to forge SAML responses and hijack user sessions.

    osintsights.com/hackers-exploi

    #Wordpress #AuthBypass #Saml #Miniorange #Cve202661979

  2. Thank you #miniOrange for generously sponsoring us their Wordpress plugin for SSO authentication!

    This allowed us to consolidate yet another service to use our unified authentication layer for #GNOME contributors.

    linkedin.com/company/miniorange

  3. Unbelievable! MiniOrange just did it again. Yet another time, they removed a plugin from the WordPress repo instead of patching it, leaving a CVSS 8.1 vulnerability on 200 sites.

    MiniOrange use code obfuscation to “prevent reverse-engineering” of their open-source plugins!? Maybe there’s another reason…

    wordfence.com/threat-intel/vul

    #WordPress #MiniOrange

  4. "WordPress users of miniOrange's Malware Scanner and Web Application Firewall plugins are being urged to delete them from their websites following the discovery of a critical security flaw" 🕵️ 🧐

    thehackernews.com/2024/03/word

    #miniorange #plugin #wordpress #cve20242172 #cybersec #cybersecurity

  5. miniOrange must be the worst WordPress developer. They not only obfuscate code. When a 9.8 CVSS CVE got discovered in two of their plugins, they closed the projects and left the vulnerabilities unresolved.

    wordfence.com/blog/2024/03/cri

    (They market their plugins as “best-in-class security solutions”.)

    #MiniOrange #CVE_2024_2172