# WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 44.1 - Authenticated (Subscriber+) Server-Side Request Forgery via Microsoft Graph Proxy

- **ID:** WPSEC-2026-0456
- **Plugin:** WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) (`wpo365-login`), https://wordpress.org/plugins/wpo365-login/
- **Affected versions:** all versions before 45.0
- **Fixed in:** 45.0 (Update to 45.0 or later.)
- **Severity:** High 7.1 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N)
- **Weakness:** CWE-918
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-06)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wpo365-login
- **Fix released:** 2026-10-04
- **Published:** 2026-10-06
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0456/

## Description

The WPO365 plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 44.1 via its Microsoft Graph proxy and batch routes and its Graph proxy AJAX action. A requested destination was compared with the administrator's list of allowed endpoints as a plain case-insensitive string prefix, so a URL such as 'https://graph.microsoft.com@attacker.tld/' or 'https://graph.microsoft.com.attacker.tld/' matched an allow-listed entry that has no path, and a separate option that let apps request any endpoint disabled the destination check entirely. Because the proxy attaches the website's Microsoft 365 access token to the outgoing request, the token is delivered to the host the caller chose. This requires the Microsoft Graph integration and proxy requests to be enabled; by default the caller must be a logged-in user who has signed in with Microsoft, any logged-in user where the administrator lowered the access level, or an unauthenticated visitor where an app was configured for anonymous access.

## References

- https://wpsec.com/vuln/WPSEC-2026-0456/
- https://plugins.svn.wordpress.org/wpo365-login/tags/45.0/
- https://wordpress.org/plugins/wpo365-login/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0456/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
