Description
Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.
Published: 2026-08-13
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an unauthenticated attacker to bypass authentication in the WordPress Headless Single Sign On plugin through a flaw enumerated as CWE-347. This flaw permits an attacker to gain access without providing valid credentials, effectively compromising the privacy and integrity of user accounts. The impact is severe because it enables unauthorized use of the system's services, potentially exposing sensitive information and allowing further malicious actions.

Affected Systems

The issue affects the miniOrange Headless Single Sign On WordPress plugin, versions 1.6 and earlier. Any WordPress installation that has these versions of the plugin installed is at risk. Upgrading to at least 1.6.1 removes the flaw.

Risk and Exploitability

The CVSS score of 9.8 marks this vulnerability as critical. While the EPSS score is not available, the lack of a KEV listing does not diminish the risk, as the flaw remains exploitable. The likely attack vector is via the plugin’s exposed authentication interface over HTTP, allowing an attacker to send crafted requests without prior authentication. Once exploited, the attacker can impersonate any user or gain unrestricted access to the site’s functions.

Generated by OpenCVE AI on August 13, 2026 at 16:35 UTC.

Remediation

Vendor Solution

Update the WordPress Headless Single Sign On plugin to the latest available version (at least 1.6.1).


OpenCVE Recommended Actions

  • Apply the latest plugin update, ensuring the version is at least 1.6.1.
  • If an upgrade cannot be performed immediately, disable or remove the Headless Single Sign On plugin from the WordPress installation.
  • Restrict direct access to the plugin’s authentication endpoints via web‑application firewall rules or IP filtering, and monitor for suspicious authentication attempts.

Generated by OpenCVE AI on August 13, 2026 at 16:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Miniorange
Miniorange headless Single Sign On
Wordpress
Wordpress wordpress
Vendors & Products Miniorange
Miniorange headless Single Sign On
Wordpress
Wordpress wordpress

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.
Title WordPress Headless Single Sign On plugin <= 1.6 - Bypass Vulnerability vulnerability
Weaknesses CWE-347
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Miniorange Headless Single Sign On
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-13T15:24:12.774Z

Reserved: 2026-02-25T12:14:24.000Z

Link: CVE-2026-28148

cve-icon Vulnrichment

Updated: 2026-08-13T15:24:08.168Z

cve-icon NVD

Status : Deferred

Published: 2026-08-13T14:16:57.943

Modified: 2026-08-14T19:09:20.713

Link: CVE-2026-28148

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T12:15:39Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature