#miniorange — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #miniorange, aggregated by home.social.
-
Hackers target #WordPress sites in #miniOrange auth bypass attacks
-
Hackers Exploit WordPress Sites in miniOrange Auth Bypass Attacks
Hackers are actively exploiting WordPress sites using a clever combination of two vulnerabilities, CVE-2026-61979 and CVE-2026-15981, to bypass authentication and gain administrator access. This stealthy attack uses the miniOrange SAML 2.0 Single Sign On plugin to forge SAML responses and hijack user sessions.
-
Thank you #miniOrange for generously sponsoring us their Wordpress plugin for SSO authentication!
This allowed us to consolidate yet another service to use our unified authentication layer for #GNOME contributors.
-
Unbelievable! MiniOrange just did it again. Yet another time, they removed a plugin from the WordPress repo instead of patching it, leaving a CVSS 8.1 vulnerability on 200 sites.
MiniOrange use code obfuscation to “prevent reverse-engineering” of their open-source plugins!? Maybe there’s another reason…
-
CVE Alert: CVE-2025-7665 - cyberlord92 - Miniorange OTP Verification with Firebase - https://www.redpacketsecurity.com/cve-alert-cve-2025-7665-cyberlord92-miniorange-otp-verification-with-firebase/
#OSINT #ThreatIntel #CyberSecurity #cve-2025-7665 #cyberlord92 #miniorange-otp-verification-with-firebase
-
"WordPress users of miniOrange's Malware Scanner and Web Application Firewall plugins are being urged to delete them from their websites following the discovery of a critical security flaw" 🕵️ 🧐
https://thehackernews.com/2024/03/wordpress-admins-urged-to-remove.html
#miniorange #plugin #wordpress #cve20242172 #cybersec #cybersecurity
-
📬 miniOrange-Plugins gefährden WordPress-Seiten
#Datenschutz #ITSicherheit #CVE20242172 #MalwareScanner #miniOrange #RegistrationMagic #Wordfence #Wordpress #WordpressPlugin https://sc.tarnkappe.info/1cdd6b -
miniOrange must be the worst WordPress developer. They not only obfuscate code. When a 9.8 CVSS CVE got discovered in two of their plugins, they closed the projects and left the vulnerabilities unresolved.
(They market their plugins as “best-in-class security solutions”.)