# WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 44.1 - Unauthenticated Authentication Bypass via Missing ID Token Issuer and Audience Validation

- **ID:** WPSEC-2026-0455
- **Plugin:** WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) (`wpo365-login`), https://wordpress.org/plugins/wpo365-login/
- **Affected versions:** all versions before 45.0
- **Fixed in:** 45.0 (Update to 45.0 or later.)
- **Severity:** Medium 6.5 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N)
- **Weakness:** CWE-287
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-06)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wpo365-login
- **Fix released:** 2026-10-04
- **Published:** 2026-10-06
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0455/

## Description

The WPO365 plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 44.1. An ID token's signature is verified against Microsoft's published signing keys and bound to the sign-in request by a nonce, but the issuer, tenant and audience were only checked in the pre-check that applies to a directly posted ID token, and not when the ID token was obtained through the authorization code flow, which is the default. On a site configured for multiple tenants with a list of allow-listed tenants, the allow-list was therefore not applied to a sign-in at all, and the deprecated options 'Skip ID token verification' and 'Use Firebase\JWT instead of phpseclib' removed the remaining checks, the latter also treating an invalid nonce as a warning only. This makes it possible for unauthenticated attackers who hold a Microsoft account in a tenant that the administrator did not allow-list to sign in to the site as themselves, receiving whatever role the site grants to new users; an existing account can only be reached where the site matches users on an identity the attacker controls.

## References

- https://wpsec.com/vuln/WPSEC-2026-0455/
- https://plugins.svn.wordpress.org/wpo365-login/tags/45.0/
- https://wordpress.org/plugins/wpo365-login/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0455/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
