What to look out for today
Two practical items for SMEs and their IT providers to check today:
- WordPress sites using SSO: reports of attackers targeting the miniOrange SAML 2.0 Single Sign On WordPress plugin with authentication bypass attempts.
- Internet-facing Oracle services: CISA has added an Oracle HTTP Server / Oracle WebLogic Server proxy plug-in issue to its Known Exploited Vulnerabilities catalogue, indicating real-world exploitation.
Why this matters to smaller businesses
- Website compromise impacts trust and revenue: a hacked WordPress site can be used to host scams, redirect customers, or steal enquiries.
- SSO is a “keys to the kingdom” dependency: if attackers can log in as an admin, they can change content, create new users, or plant further access.
- Oracle/WebLogic often sits behind critical apps: even if you don’t run it directly, a supplier, hosted platform, or MSP-managed environment might.
Warning signs
- Unexpected new WordPress admin users, or admin accounts you don’t recognise.
- SSO behaving oddly (users being logged in without prompts, admin sessions appearing you can’t explain).
- Website content changes, new plugins installed, or security plugins disabled without approval.
- Spikes in web server traffic, repeated login attempts, or unusual authentication logs around SAML/SSO.
- For business apps: unexplained data access, new service accounts, or configuration changes in hosted environments.
How attackers may exploit the situation
- WordPress SSO bypass: attackers may attempt to forge or bypass authentication to gain administrator access, then persist by creating accounts, changing settings, or adding malicious components.
- Actively exploited Oracle issue: attackers commonly scan for exposed services and use known, working techniques once exploitation is confirmed in the wild. This can lead to unauthorised access and data exposure, especially where systems are reachable from the internet.
What to do today
- Confirm whether you use the affected WordPress plugin: ask whoever manages your site (internal, agency, or MSP) to verify if miniOrange SAML SSO is installed and whether there’s any suspicious admin activity.
- Review WordPress admin access: remove unknown admin users, enforce MFA for admin accounts, and ensure only required accounts have admin rights.
- Check supplier/hosted platforms for Oracle/WebLogic exposure: if you have any line-of-business apps, portals, or older Java-based platforms, ask vendors/IT whether Oracle HTTP Server/WebLogic components are in use and internet-facing.
- Increase monitoring today: ensure website change alerts and admin-login alerts are enabled (or temporarily turned on) and that logs are retained.
- Be ready for rapid containment: know who can take the website offline, restore from backup, and rotate credentials quickly if compromise is suspected.
Ask your IT provider
- Do any of our WordPress sites use miniOrange SAML 2.0 SSO, and have you checked for unexpected admin logins or new admin users in the last 7 days?
- Do we (or any key suppliers) run Oracle HTTP Server / WebLogic components, and are any of them reachable from the internet?
- What monitoring/alerts do we have for: new admin accounts, plugin changes, and website file integrity changes?
- If our site/app is compromised today, what is the restore point objective (how far back) and restore time (how quickly) from backup?
Patch watch - only one short paragraph, and only if relevant
CISA has flagged an Oracle HTTP Server / WebLogic proxy plug-in vulnerability as actively exploited, which usually means organisations should treat it as an urgent remediation item (including supplier confirmation if you don’t manage the platform directly). Separately, if your WordPress site uses miniOrange SAML SSO, prioritise validation and remediation with your website maintainer to reduce the risk of admin account takeover.
One action today
Ask your website maintainer today to confirm whether any of your WordPress sites use miniOrange SAML SSO and to audit for any unexpected admin logins or new admin users in the last week.
Related Actions On Cyber resource
Actions On Cyber checklist CTA: “WordPress & website security quick check (admin access, MFA, backups, change monitoring)”
Sources
- Hackers target WordPress sites in miniOrange auth bypass attacks (BleepingComputer)
- CISA Adds One Known Exploited Vulnerability to Catalog (CISA Cybersecurity Advisories)
- Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data (The Hacker News)
This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.