Follow the latest coverage, related explainers and connected technology stories.
Researchers are monitoring attempts to exploit two critical vulnerabilities in the miniOrange SAML 2.0 Single Sign-On plugin that could enable the forgery of SAML responses and login with WordPress administrator accounts. The fixes cover all free and paid versions, but the paid versions do not display update notifications in the administration dashboard.