WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 44.1 - Authenticated (Subscriber+) Server-Side Request Forgery via Microsoft Graph Proxy

High 7.1 CWE-918Fixed in 45.0
ID
WPSEC-2026-0456
Plugin
WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) (wpo365-login)
Affected
all versions before 45.0
Remediation
Update to 45.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N
Weakness
CWE-918
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-06
Attack surface
WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) on WPSec AttackSurface
Fix released
Published

Description

The WPO365 plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 44.1 via its Microsoft Graph proxy and batch routes and its Graph proxy AJAX action. A requested destination was compared with the administrator's list of allowed endpoints as a plain case-insensitive string prefix, so a URL such as 'https://[email protected]/' or 'https://graph.microsoft.com.attacker.tld/' matched an allow-listed entry that has no path, and a separate option that let apps request any endpoint disabled the destination check entirely. Because the proxy attaches the website's Microsoft 365 access token to the outgoing request, the token is delivered to the host the caller chose. This requires the Microsoft Graph integration and proxy requests to be enabled; by default the caller must be a logged-in user who has signed in with Microsoft, any logged-in user where the administrator lowered the access level, or an unauthenticated visitor where an app was configured for anonymous access.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0