WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 44.1 - Unauthenticated Authentication Bypass via Missing ID Token Issuer and Audience Validation

Medium 6.5 CWE-287Fixed in 45.0
ID
WPSEC-2026-0455
Plugin
WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) (wpo365-login)
Affected
all versions before 45.0
Remediation
Update to 45.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Weakness
CWE-287
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-06
Attack surface
WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) on WPSec AttackSurface
Fix released
Published

Description

The WPO365 plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 44.1. An ID token's signature is verified against Microsoft's published signing keys and bound to the sign-in request by a nonce, but the issuer, tenant and audience were only checked in the pre-check that applies to a directly posted ID token, and not when the ID token was obtained through the authorization code flow, which is the default. On a site configured for multiple tenants with a list of allow-listed tenants, the allow-list was therefore not applied to a sign-in at all, and the deprecated options 'Skip ID token verification' and 'Use Firebase\JWT instead of phpseclib' removed the remaining checks, the latter also treating an invalid nonce as a warning only. This makes it possible for unauthenticated attackers who hold a Microsoft account in a tenant that the administrator did not allow-list to sign in to the site as themselves, receiving whatever role the site grants to new users; an existing account can only be reached where the site matches users on an identity the attacker controls.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0