CVE-2026-28149

9.8

miniOrange · Headless Single Sign On

The miniOrange Headless Single Sign On plugin for WordPress contains an unauthenticated PHP object injection vulnerability in versions 1.6 and earlier.

Executive summary

An unauthenticated PHP object injection vulnerability in the miniOrange Headless Single Sign On plugin permits remote attackers to achieve total system impact.

Vulnerability

The plugin is susceptible to CWE-502, which involves the deserialization of untrusted data. This flaw allows an unauthenticated attacker to inject malicious PHP objects, potentially leading to remote code execution or other significant impacts on the host server.

Business impact

With a CVSS score of 9.8, this vulnerability poses a critical threat to the security of the WordPress instance. An attacker could potentially gain full control over the affected site, leading to unauthorized access to user data, site defacement, or the deployment of malicious software, resulting in significant reputational and operational damage.

Remediation

Immediate Action: Update the miniOrange Headless Single Sign On plugin to version 1.6.1 or later to remediate the deserialization flaw.

Proactive Monitoring: Monitor WordPress installation logs for signs of unauthorized file modifications or unexpected PHP execution patterns.

Compensating Controls: Ensure that a WAF is deployed to filter malicious serialized objects from incoming HTTP requests.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the critical nature of this vulnerability and its potential for unauthenticated exploitation, administrators should update the plugin immediately. Ensure all plugins are kept at the latest version to prevent similar risks in the future.

More miniOrange CVEs