WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 44.1 - Authenticated (Subscriber+) Missing Authorization to Application-Level Microsoft Graph Access via 'application' Parameter

High 8.2 CWE-285Fixed in 45.0
ID
WPSEC-2026-0458
Plugin
WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) (wpo365-login)
Affected
all versions before 45.0
Remediation
Update to 45.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Weakness
CWE-285
Usage
Plugin Medium · Affected versions Medium among sites WPSec scans, 2026-10-06
Attack surface
WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) on WPSec AttackSurface
Fix released
Published

Description

The WPO365 plugin for WordPress is vulnerable to unauthorized use of application-level Microsoft 365 permissions in all versions up to, and including, 44.1. The Microsoft Graph proxy, batch and file-upload handlers let the request itself decide, through an 'application' parameter and the scope it asked for, that the website's own application credentials should be used, without honouring the administrator's per-endpoint setting for application-level permissions; the mail application's credentials were selected whenever the caller-supplied scope merely contained 'Mail.Send' or 'Mail.ReadWrite', and the role comparison was a substring match. The token route likewise returned an application-level token to the browser for a resource-wide '.default' scope. This makes it possible for callers who can reach these routes to read and write Microsoft 365 data, send mail and obtain access tokens with the website's own permissions instead of their own. Exploitation requires the site to have configured application-level credentials and to have been granted the corresponding application permissions; by default the caller must be a logged-in user who has signed in with Microsoft, any logged-in user where the administrator lowered the access level, or an unauthenticated visitor where an app was configured for anonymous access.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0