# WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 44.1 - Unauthenticated Stored Cross-Site Scripting via ID Token Claims in Health Messages

- **ID:** WPSEC-2026-0457
- **Plugin:** WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) (`wpo365-login`), https://wordpress.org/plugins/wpo365-login/
- **Affected versions:** all versions before 45.0
- **Fixed in:** 45.0 (Update to 45.0 or later.)
- **Severity:** High 7.2 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N)
- **Weakness:** CWE-79
- **Usage among sites WPSec scans:** plugin Medium, affected versions Medium (as of 2026-10-06)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/wpo365-login
- **Fix released:** 2026-10-04
- **Published:** 2026-10-06
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0457/

## Description

The WPO365 plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 44.1 due to insufficient sanitization of values read from a posted OpenID Connect ID token before its signature is verified. The issuer, audience and user-name claims of such a token are written verbatim into the plugin's error messages, the most recent of which are stored and later rendered as HTML in the plugin's health messages in WP Admin. This makes it possible for unauthenticated attackers, who need no valid Microsoft-issued token, to inject arbitrary web scripts that execute when an administrator views the plugin's health messages.

## References

- https://wpsec.com/vuln/WPSEC-2026-0457/
- https://plugins.svn.wordpress.org/wpo365-login/tags/45.0/
- https://wordpress.org/plugins/wpo365-login/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0457/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
