CVE-2026-62108: WordPress Headless Single Sign On plugin <= 1.7.0 - Broken Authentication vulnerability
Published Sep 17, 2026
·Updated
Unauthenticated Broken Authentication in Headless Single Sign On <= 1.7.0 versions.
Affected Software
1 affected component
wordpress-plugin/headless-single-sign-on<=1.7.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Headless Single Sign On pluginto a version that resolves this vulnerability.Fixed in 1.7.1
Event History
Sep 17, 2026
CVE Published
via MITRE·01:24 PM
Data Sourced
via MITRE·01:24 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
No authentication or prior privileges are required. The listed vector indicates the attack can be performed remotely over the network without user interaction.
2
What versions are affected?
Headless Single Sign On plugin versions 1.7.0 and earlier are identified as affected.
3
What is the potential impact of successful exploitation?
Successful exploitation can compromise confidentiality, integrity, and availability at a high level. The vulnerability is rated critical with a CVSS score of 9.8.