Authentication Bypass in WPO365 | Login Plugin for WordPress
CVE-2026-104759
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-104759?
The WPO365 | Login plugin for WordPress suffers from an authentication bypass vulnerability due to a flaw in the nonce verification process. The plugin leverages the wp_verify_nonce() function to validate a nonce generated by the Nonce_Service::create_nonce(). However, the nonce produced is a 64-character hex value incompatible with the verification method, leading the check to fail silently. This allows attackers to replay previously issued valid id_token tokens for unauthorized access to any WordPress user account, including those with administrative privileges. It is important to note that this vulnerability is exploitable only when the use_id_token_parser_v2 option is activated, thus routing token processing through a deprecated parser that lacks proper nonce validation.
Affected Version(s)
WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) 0 <= 44.1