CVE-2026-28148: WordPress Headless Single Sign On plugin <= 1.6 - Bypass Vulnerability vulnerability
Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Headless Single Sign On pluginto a version that resolves this vulnerability.Fixed in 1.6.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28148?
The severity of CVE-2026-28148 is critical with a score of 9.8.
What is CVE-2026-28148?
CVE-2026-28148 is an unauthenticated bypass vulnerability in the Headless Single Sign On plugin for WordPress versions 1.6 and below.
How do I fix CVE-2026-28148?
To fix CVE-2026-28148, you should update the Headless Single Sign On plugin to a version above 1.6.
What are the potential impacts of CVE-2026-28148?
The potential impacts of CVE-2026-28148 include unauthorized access and data exposure due to the bypass vulnerability.
Who is affected by CVE-2026-28148?
Users of the Headless Single Sign On plugin for WordPress versions up to 1.6 are affected by CVE-2026-28148.