One slug, seven editions: the miniOrange SAML SSO bug that let anyone log in as your WordPress admin
SAML Single Sign On
Authentication Bypass
Reported by the DigitalOcean security team, with root cause analysis by DigitalOcean, coverage and vendor follow-up handled jointly with Patchstack.
Most vulnerability write-ups are about the bug. This is primarily about everything around the bug, where the actual risk ended up living.…