Vulnerabilities (CVE)

Filtered by vendor Miniorange Subscribe
Total 43 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-6850 1 Miniorange 1 Saml Sp Single Sign On 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
Utilities.php in the miniorange-saml-20-single-sign-on plugin before 4.8.84 for WordPress allows XSS via a crafted SAML XML Response to wp-login.php. This is related to the SAMLResponse and RelayState variables, and the Destination parameter of the samlp:Response XML element.
CVE-2019-12346 1 Miniorange 1 Saml Sp Single Sign On 2024-11-21 4.3 MEDIUM 6.1 MEDIUM
In the miniOrange SAML SP Single Sign On plugin before 4.8.73 for WordPress, the SAML Login Endpoint is vulnerable to XSS via a specially crafted SAMLResponse XML post.
CVE-2022-4539 1 Miniorange 1 Web Application Firewall 2024-09-19 N/A 5.3 MEDIUM
The Web Application Firewall plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 2.1.2. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header with with a different IP Address that will be logged and can be used to bypass settings that may have blocked out an IP address or country from logging in.