Two miniOrange SAML WordPress plugin auth bypasses were exploited while paid editions never appeared in any vulnerability ...