{
 "id": "WPSEC-2026-0456",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0456/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0456/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0456/index.md",
 "title": "WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 44.1 - Authenticated (Subscriber+) Server-Side Request Forgery via Microsoft Graph Proxy",
 "description": "The WPO365 plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 44.1 via its Microsoft Graph proxy and batch routes and its Graph proxy AJAX action. A requested destination was compared with the administrator's list of allowed endpoints as a plain case-insensitive string prefix, so a URL such as 'https://graph.microsoft.com@attacker.tld/' or 'https://graph.microsoft.com.attacker.tld/' matched an allow-listed entry that has no path, and a separate option that let apps request any endpoint disabled the destination check entirely. Because the proxy attaches the website's Microsoft 365 access token to the outgoing request, the token is delivered to the host the caller chose. This requires the Microsoft Graph integration and proxy requests to be enabled; by default the caller must be a logged-in user who has signed in with Microsoft, any logged-in user where the administrator lowered the access level, or an unauthenticated visitor where an app was configured for anonymous access.",
 "plugin": {
  "slug": "wpo365-login",
  "name": "WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN)",
  "full_name": "WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN)",
  "wordpress_org": "https://wordpress.org/plugins/wpo365-login/",
  "advisories_url": "https://wpsec.com/vuln/plugin/wpo365-login/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/wpo365-login"
 },
 "type": "SSRF",
 "cwe": [
  "CWE-918"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 7.1,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N",
  "severity": "High"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "45.0",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 45.0"
  ]
 },
 "introduced_in": null,
 "fixed_in": "45.0",
 "remediation": "Update to 45.0 or later.",
 "fix_released": "2026-10-04T12:31:32+00:00",
 "published": "2026-10-06T16:45:40+00:00",
 "updated": "2026-10-06T16:17:15.509981+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0456/",
  "https://plugins.svn.wordpress.org/wpo365-login/tags/45.0/",
  "https://wordpress.org/plugins/wpo365-login/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/wpo365-login",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Medium",
  "as_of": "2026-10-06"
 }
}