Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.
Update the WordPress Headless Single Sign On plugin to the latest available version (at least 1.6.1).