LiveActive security incident?Get immediate response
CVE Record

CVE-2026-28148: WordPress Headless Single Sign On plugin <= 1.6 - Bypass Vulnerability vulnerability

Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.

CriticalCVSS 9.8Not KEV-listedUpdated
Glexia's TakeAutomated analysiscritical

Security readout for executives and security teams

Plain-English summary

This critical flaw may let an unauthenticated remote attacker bypass protections in the WordPress Headless Single Sign On plugin through version 1.6. The assigned severity indicates possible compromise of sensitive data, site integrity, and availability. Public details are limited, so the exact bypass outcome and required configuration remain unclear.

Executive priority

Treat as an urgent exposure-validation and remediation task for internet-facing WordPress systems. The 9.8 score and unauthenticated network vector justify rapid action, while the absence of confirmed exploitation and incomplete technical details argue for evidence-based scoping rather than declaring compromise.

Technical view

CVE-2026-28148 is classified as CWE-347, improper verification of a cryptographic signature. Its CVSS 3.1 vector describes network access, low complexity, no privileges, and no user interaction, with high confidentiality, integrity, and availability impact. The bundle identifies versions through 1.6, but its structured affected record does not provide a precise version range.

Likely exposure

Potential exposure is limited to WordPress installations using the miniOrange Headless Single Sign On plugin, reportedly through version 1.6. Internet-accessible deployments warrant the fastest review. The sources do not identify vulnerable configurations, endpoint prerequisites, installation prevalence, or whether every deployment running those versions is exploitable.

Exploitation context

The CVE is not listed in the supplied KEV data, and the provided sources do not report active exploitation or public exploit availability. The CVSS assessment indicates favorable theoretical attack conditions, but no exploit mechanics, observed campaigns, or reliable indicators of compromise are supplied.

Researcher notes

The public bundle does not describe the faulty verification path, affected request flow, prerequisites, fixed release, or indicators. CWE-347 suggests signature-verification failure, but the exact implementation defect is not established. The title says versions through 1.6, while the structured affected entry lists versions as unavailable and defaults to unaffected; verify vendor metadata.

Mitigation direction

  • Inventory WordPress sites for the headless-single-sign-on plugin and record installed versions.
  • Prioritize internet-facing installations reportedly running version 1.6 or earlier.
  • Check miniOrange and Patchstack guidance for a confirmed fixed version or vendor-approved mitigation.
  • If no fix is confirmed, assess disabling the plugin or restricting exposure under change control.
  • Monitor authentication and administrative activity for unexplained access or account changes.

Validation and detection

  • Confirm the plugin slug, activation state, version, and internet accessibility on every WordPress installation.
  • Verify remediation against current miniOrange or Patchstack guidance before closing the finding.
  • Review SSO, WordPress, proxy, and security logs for anomalous unauthenticated activity.
  • Retest legitimate SSO and administrative workflows after mitigation without attempting offensive exploitation.
  • Document systems where the plugin is absent, disabled, or outside the reported affected range.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-347: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2026-28148 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Critical
CVSS
9.8 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
1ADP providers
2Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: yesTechnical Impact: total

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
9.8CVSS 3.1CriticalCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H3.95.9Patchstack

Vulnerability scoring details

Base CVSS 3.1 score

9.8Critical
CVSS 3.1 vector shape for CVE-2026-28148Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc
Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
miniOrangeHeadless Single Sign Onheadless-single-sign-on, n/aunaffected
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-347 · source CWE mapping

Improper Verification of Cryptographic Signature

Improper Verification of Cryptographic Signature represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.