Impact
The vulnerability lies in the authentication mechanism of the miniOrange Headless Single Sign On plugin for WordPress, affecting all released versions up to and including 1.7.0. The flaw allows an attacker to skip the normal authentication step and obtain privileged access without possessing valid credentials. This breach in authentication control is classified as CWE‑290, representing broken authentication.
Affected Systems
WordPress sites that have the miniOrange Headless Single Sign On plugin installed with a version of 1.7.0 or older are affected. The plugin is used to enable headless authentication for WordPress installations. Any installation that has not yet upgraded to the patched release remains vulnerable until remediation is applied.
Risk and Exploitability
The CVSS score of 9.8 signals critical severity. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog, but the ability to bypass authentication without any preconditions makes it straightforward for remote attackers to exploit. Attackers can target the site over HTTP(S) and trigger the flaw via the plugin’s exposed endpoints, giving them potential access to administrative capabilities. Consequently, timely patching is strongly advised.
OpenCVE Enrichment