Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-62108: WordPress Headless Single Sign On lets attackers bypass login

CVE-2026-62108 · published 23 days ago
Summary

The Headless Single Sign On plug‑in for WordPress, up to version 1.7.0, does not properly verify who is trying to log in. This means someone without credentials could gain access to the site as an admin or other user. Update the plug‑in to the latest version or remove it if it is not needed.

What to do
  • Update miniorange headless single sign on to version 1.7.1.
Affected software
VendorProductAffected versions
miniorange headless single sign on <= 1.7.0
Fix: upgrade to 1.7.1
Original advisory text
WordPress Headless Single Sign On plugin <= 1.7.0 - Broken Authentication vulnerability
Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-290Authentication Bypass by Spoofing
Timeline
Published17 Sep 2026
Updated7 Oct 2026
First seen17 Sep 2026
Sources
CVE-2026-62108 · MITRE
Track software like this
Free during beta