MERENA
Immediate Action Alert

Hackers could use this WordPress login flaw to get into any account

Attackers are trying to take over WordPress websites by abusing a serious flaw in the miniOrange SAML login plugin. If successful, they could sign in as any user, including the site owner or administrator, without permission.


Who is at risk

Organizations, businesses, schools, and individuals who run a WordPress site using the miniOrange SAML 2.0 Single Sign On plugin are most at risk.

What to watch for

Watch for unexpected logins, changes to site settings, new administrator accounts, or other website changes that you did not make.

What to do

Immediately update or disable the affected miniOrange SAML plugin, review administrator accounts, and check recent login activity for anything suspicious.