{
 "id": "WPSEC-2026-0458",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0458/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0458/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0458/index.md",
 "title": "WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 44.1 - Authenticated (Subscriber+) Missing Authorization to Application-Level Microsoft Graph Access via 'application' Parameter",
 "description": "The WPO365 plugin for WordPress is vulnerable to unauthorized use of application-level Microsoft 365 permissions in all versions up to, and including, 44.1. The Microsoft Graph proxy, batch and file-upload handlers let the request itself decide, through an 'application' parameter and the scope it asked for, that the website's own application credentials should be used, without honouring the administrator's per-endpoint setting for application-level permissions; the mail application's credentials were selected whenever the caller-supplied scope merely contained 'Mail.Send' or 'Mail.ReadWrite', and the role comparison was a substring match. The token route likewise returned an application-level token to the browser for a resource-wide '.default' scope. This makes it possible for callers who can reach these routes to read and write Microsoft 365 data, send mail and obtain access tokens with the website's own permissions instead of their own. Exploitation requires the site to have configured application-level credentials and to have been granted the corresponding application permissions; by default the caller must be a logged-in user who has signed in with Microsoft, any logged-in user where the administrator lowered the access level, or an unauthenticated visitor where an app was configured for anonymous access.",
 "plugin": {
  "slug": "wpo365-login",
  "name": "WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN)",
  "full_name": "WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN)",
  "wordpress_org": "https://wordpress.org/plugins/wpo365-login/",
  "advisories_url": "https://wpsec.com/vuln/plugin/wpo365-login/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/wpo365-login"
 },
 "type": "NO AUTHORISATION",
 "cwe": [
  "CWE-285"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 8.2,
  "vector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N",
  "severity": "High"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "45.0",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 45.0"
  ]
 },
 "introduced_in": null,
 "fixed_in": "45.0",
 "remediation": "Update to 45.0 or later.",
 "fix_released": "2026-10-04T12:31:32+00:00",
 "published": "2026-10-06T16:45:40+00:00",
 "updated": "2026-10-06T16:17:15.509981+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0458/",
  "https://plugins.svn.wordpress.org/wpo365-login/tags/45.0/",
  "https://wordpress.org/plugins/wpo365-login/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/wpo365-login",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Medium",
  "affected_versions": "Medium",
  "as_of": "2026-10-06"
 }
}