WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 44.1 - Unauthenticated Stored Cross-Site Scripting via ID Token Claims in Health Messages
- ID
- WPSEC-2026-0457
- Plugin
- WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) (wpo365-login)
- Affected
- all versions before 45.0
- Remediation
- Update to 45.0 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
- Weakness
- CWE-79
- Usage
- Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-06
- Attack surface
- WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) on WPSec AttackSurface
- Fix released
- Published
Description
The WPO365 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 44.1 due to insufficient sanitization of values read from a posted OpenID Connect ID token before its signature is verified. The issuer, audience and user-name claims of such a token are written verbatim into the plugin's error messages, the most recent of which are stored and later rendered as HTML in the plugin's health messages in WP Admin. This makes it possible for unauthenticated attackers, who need no valid Microsoft-issued token, to inject arbitrary web scripts that execute when an administrator views the plugin's health messages.
References
- https://wpsec.com/vuln/WPSEC-2026-0457/
- https://plugins.svn.wordpress.org/wpo365-login/tags/45.0/
- https://wordpress.org/plugins/wpo365-login/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS