WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 43.2 - Cross-Site Request Forgery to Privilege Escalation via Plugin Settings Update
high
The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. This is due to the Ajax_Service::verify_ajax_request() helper gating its wp_verify_nonce() call behind the boolean option 'enable_nonce_check', which is absent from the default 'wpo365_options' ar...
- CVSS:
- 8.8
- Affected:
- up to 43.2
- Fixed in:
- 43.3
- Disclosed:
- Jul 23, 2026
CVE-2026-15212 on NVD →
WPO365 <= 40.0 - Authenticated (Subscriber+) Server-Side Request Forgery
medium
The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 40.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations o...
- CVSS:
- 6.4
- Affected:
- up to 40.0
- Fixed in:
- 40.1
- Disclosed:
- Jan 21, 2026
CVE-2025-67961 on NVD →
WordPress + Microsoft Office 365 / Azure AD | LOGIN <= 27.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via pintra Shortcode
medium
The WordPress + Microsoft Office 365 / Azure AD | LOGIN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pintra' shortcode in all versions up to, and including, 27.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for auth...
- CVSS:
- 6.4
- Affected:
- up to 27.2
- Fixed in:
- 28.0
- Disclosed:
- May 22, 2024
CVE-2024-4706 on NVD →
WordPress + Microsoft Office 365 / Azure AD | LOGIN <= 15.3 - Stored Cross-Site Scripting
medium
The WPO365 | LOGIN WordPress plugin (up to and including version 15.3) by wpo365.com is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability (also known as Stored or Second-Order XSS). Persistent XSS vulnerabilities occur when the application stores and retrieves client supplied data without proper handl...
- CVSS:
- 6.1
- Affected:
- up to 15.3
- Fixed in:
- 15.4
- Disclosed:
- Oct 15, 2021
CVE-2021-43409 on NVD →
WPO365 | LOGIN <= 11.6 - Authentication Bypass
critical
The WPO365 | LOGIN plugin before v11.7 for WordPress allows use of a symmetric algorithm to decrypt a JWT token. This leads to authentication bypass.
- CVSS:
- 9.1
- Affected:
- up to 11.6
- Fixed in:
- 11.7
- Disclosed:
- Oct 2, 2020
CVE-2020-26511 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database