plugin

Wpo365 Login Vulnerabilities

5 known security issues reported for the Wpo365 Login WordPress plugin. Most recent disclosed Jul 23, 2026.

1 critical 1 high 3 medium

Running Wpo365 Login on your site? Check whether your installed version is affected.

Scan your site free

WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 43.2 - Cross-Site Request Forgery to Privilege Escalation via Plugin Settings Update

high

The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. This is due to the Ajax_Service::verify_ajax_request() helper gating its wp_verify_nonce() call behind the boolean option 'enable_nonce_check', which is absent from the default 'wpo365_options' ar...

CVSS:
8.8
Affected:
up to 43.2
Fixed in:
43.3
Disclosed:
Jul 23, 2026

CVE-2026-15212 on NVD →

WPO365 <= 40.0 - Authenticated (Subscriber+) Server-Side Request Forgery

medium

The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 40.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to make web requests to arbitrary locations o...

CVSS:
6.4
Affected:
up to 40.0
Fixed in:
40.1
Disclosed:
Jan 21, 2026

CVE-2025-67961 on NVD →

WordPress + Microsoft Office 365 / Azure AD | LOGIN <= 27.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via pintra Shortcode

medium

The WordPress + Microsoft Office 365 / Azure AD | LOGIN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pintra' shortcode in all versions up to, and including, 27.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for auth...

CVSS:
6.4
Affected:
up to 27.2
Fixed in:
28.0
Disclosed:
May 22, 2024

CVE-2024-4706 on NVD →

WordPress + Microsoft Office 365 / Azure AD | LOGIN <= 15.3 - Stored Cross-Site Scripting

medium

The WPO365 | LOGIN WordPress plugin (up to and including version 15.3) by wpo365.com is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability (also known as Stored or Second-Order XSS). Persistent XSS vulnerabilities occur when the application stores and retrieves client supplied data without proper handl...

CVSS:
6.1
Affected:
up to 15.3
Fixed in:
15.4
Disclosed:
Oct 15, 2021

CVE-2021-43409 on NVD →

WPO365 | LOGIN <= 11.6 - Authentication Bypass

critical

The WPO365 | LOGIN plugin before v11.7 for WordPress allows use of a symmetric algorithm to decrypt a JWT token. This leads to authentication bypass.

CVSS:
9.1
Affected:
up to 11.6
Fixed in:
11.7
Disclosed:
Oct 2, 2020

CVE-2020-26511 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database