CVE-2026-28148
9.8miniOrange · Headless Single Sign On
The miniOrange Headless Single Sign On plugin for WordPress contains an unauthenticated bypass vulnerability due to improper cryptographic signature verification.
Executive summary
A critical vulnerability in the miniOrange Headless Single Sign On plugin allows unauthenticated attackers to bypass security checks and gain unauthorized access.
Vulnerability
This is an improper verification of cryptographic signature vulnerability (CWE-347). The flaw allows an unauthenticated attacker to bypass the intended authentication mechanism, granting them unauthorized access to the system.
Business impact
Exploitation of this vulnerability allows unauthorized actors to bypass authentication controls, potentially leading to full system compromise. Given the CVSS score of 9.8, this poses a severe risk to the confidentiality and integrity of any WordPress site utilizing this plugin for headless authentication.
Remediation
Immediate Action: Update the Headless Single Sign On plugin to version 1.6.1 or later to resolve the signature verification flaw.
Proactive Monitoring: Audit access logs for unauthorized entry attempts or anomalous session tokens that do not originate from legitimate identity providers.
Compensating Controls: If immediate patching is not feasible, restrict access to the affected authentication endpoints or deactivate the plugin entirely.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability is critical and requires immediate attention. Security teams must ensure that the plugin is updated to the fixed version 1.6.1 to prevent unauthorized access. Given that the vulnerability resides in the authentication layer, failure to patch leaves the entire application exposed to remote attackers.