Hackers could use this WordPress login flaw to get into any account
Attackers are trying to take over WordPress websites by abusing a serious flaw in the miniOrange SAML login plugin. If successful, they could sign in as any user, including the site owner or administrator, without permission.
Who is at risk
Organizations, businesses, schools, and individuals who run a WordPress site using the miniOrange SAML 2.0 Single Sign On plugin are most at risk.
What to watch for
Watch for unexpected logins, changes to site settings, new administrator accounts, or other website changes that you did not make.
What to do
Immediately update or disable the affected miniOrange SAML plugin, review administrator accounts, and check recent login activity for anything suspicious.
