CVE-2026-28149
9.8miniOrange · Headless Single Sign On
The miniOrange Headless Single Sign On plugin for WordPress contains an unauthenticated PHP object injection vulnerability in versions 1.6 and earlier.
Executive summary
An unauthenticated PHP object injection vulnerability in the miniOrange Headless Single Sign On plugin permits remote attackers to achieve total system impact.
Vulnerability
The plugin is susceptible to CWE-502, which involves the deserialization of untrusted data. This flaw allows an unauthenticated attacker to inject malicious PHP objects, potentially leading to remote code execution or other significant impacts on the host server.
Business impact
With a CVSS score of 9.8, this vulnerability poses a critical threat to the security of the WordPress instance. An attacker could potentially gain full control over the affected site, leading to unauthorized access to user data, site defacement, or the deployment of malicious software, resulting in significant reputational and operational damage.
Remediation
Immediate Action: Update the miniOrange Headless Single Sign On plugin to version 1.6.1 or later to remediate the deserialization flaw.
Proactive Monitoring: Monitor WordPress installation logs for signs of unauthorized file modifications or unexpected PHP execution patterns.
Compensating Controls: Ensure that a WAF is deployed to filter malicious serialized objects from incoming HTTP requests.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the critical nature of this vulnerability and its potential for unauthenticated exploitation, administrators should update the plugin immediately. Ensure all plugins are kept at the latest version to prevent similar risks in the future.