Known vulnerabilities in Headless SSO Plugin for WP
Headless SSO Plugin allows SSO login into any frontend application React, Flutter, Angular, Gatsby, etc via WordPress and Identity Providers.
3Reported vulnerabilities
8.1Highest CVSS score
1.6.1Latest version
10+Active installs
What to do now
Update Headless SSO Plugin for WP to 1.7.1 or later.
3 of these have a fixed version available. Updating resolves them.
Reported vulnerabilities
| CVE | Severity | Exploit probability |
Affected versions | Fixed in | Published |
|---|---|---|---|---|---|
| CVE-2026-28149 | High | 0.4% | 1.6 and earlier | 1.6.1 |
August 12, 2026 |
| CVE-2026-62108 | High | 0.4% | 1.7.0 and earlier | 1.7.1 |
September 15, 2026 |
| CVE-2026-28148 | Medium | 0.2% | 1.6 and earlier | 1.6.1 |
August 12, 2026 |