Executive brief
Headless Single Sign On is a WordPress plugin that manages user authentication and login for websites. Versions 1.7.0 and earlier contain a critical authentication flaw that allows attackers to bypass the login system entirely and log in as any user without a password. This vulnerability has a CVSS score of 9.8 and could lead to complete account takeover and unauthorized access to sensitive website functions and customer data.
Technical details
This is a broken authentication vulnerability (OWASP A7) in the Headless Single Sign On WordPress plugin versions 1.7.0 and earlier. The vulnerability allows unauthenticated attackers to bypass the plugin's login mechanism and gain access as arbitrary users without requiring valid credentials. No special privileges or user interaction are required for exploitation; the attack is network-accessible and can be performed by any remote attacker. The flaw has been patched in version 1.7.1. Patchstack has released a mitigation rule to block attacks against unpatched installations.
Affected products
- miniOrange Headless Single Sign On <= 1.7.0
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: Version 1.7.1 released