Impact
The vulnerability allows an unauthenticated attacker to bypass authentication in the WordPress Headless Single Sign On plugin through a flaw enumerated as CWE-347. This flaw permits an attacker to gain access without providing valid credentials, effectively compromising the privacy and integrity of user accounts. The impact is severe because it enables unauthorized use of the system's services, potentially exposing sensitive information and allowing further malicious actions.
Affected Systems
The issue affects the miniOrange Headless Single Sign On WordPress plugin, versions 1.6 and earlier. Any WordPress installation that has these versions of the plugin installed is at risk. Upgrading to at least 1.6.1 removes the flaw.
Risk and Exploitability
The CVSS score of 9.8 marks this vulnerability as critical. While the EPSS score is not available, the lack of a KEV listing does not diminish the risk, as the flaw remains exploitable. The likely attack vector is via the plugin’s exposed authentication interface over HTTP, allowing an attacker to send crafted requests without prior authentication. Once exploited, the attacker can impersonate any user or gain unrestricted access to the site’s functions.
OpenCVE Enrichment