WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 44.1 - Authenticated (Subscriber+) Server-Side Request Forgery via Microsoft Graph Proxy
- ID
- WPSEC-2026-0456
- Plugin
- WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) (wpo365-login)
- Affected
- all versions before 45.0
- Remediation
- Update to 45.0 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N
- Weakness
- CWE-918
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-06
- Attack surface
- WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) on WPSec AttackSurface
- Fix released
- Published
Description
The WPO365 plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 44.1 via its Microsoft Graph proxy and batch routes and its Graph proxy AJAX action. A requested destination was compared with the administrator's list of allowed endpoints as a plain case-insensitive string prefix, so a URL such as 'https://[email protected]/' or 'https://graph.microsoft.com.attacker.tld/' matched an allow-listed entry that has no path, and a separate option that let apps request any endpoint disabled the destination check entirely. Because the proxy attaches the website's Microsoft 365 access token to the outgoing request, the token is delivered to the host the caller chose. This requires the Microsoft Graph integration and proxy requests to be enabled; by default the caller must be a logged-in user who has signed in with Microsoft, any logged-in user where the administrator lowered the access level, or an unauthenticated visitor where an app was configured for anonymous access.
References
- https://wpsec.com/vuln/WPSEC-2026-0456/
- https://plugins.svn.wordpress.org/wpo365-login/tags/45.0/
- https://wordpress.org/plugins/wpo365-login/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS