Hackers Actively Exploit miniOrange Auth Bypass Zero-Day on WordPress Sites
Cybersecurity agencies have issued urgent patching notices as malicious actors exploit an unauthenticated authentication bypass vulnerability in miniOrange WordPress plugins.
Subscribe to Tech Bytes Briefing
Get the latest breaking tech news, AI research breakthroughs, and deep-dive analysis delivered directly to your inbox daily.
Join 50,000+ engineers & tech leaders. Zero spam. Unsubscribe anytime.
Tracked with CVSS score 9.8, the flaw allows unauthenticated remote attackers to forge JSON Web Tokens (JWT) and gain full administrative privileges over affected websites. Incident response teams report widespread automated exploitation scans targeting vulnerable e-commerce portals.
Site owners are advised to update miniOrange plugins to version 6.4.2 immediately or remove affected SSO modules.