miniOrange SAML SSO WordPress Vulnerability: One Slug, Seven Editions at Risk
Two critical CVEs let attackers forge a SAML response and log in as any WordPress user, but only the free edition was ever listed in public advisories. Here is what changed and what site owners should do.