Authentication Bypass in WPO365 | Login Plugin for WordPress
CVE-2026-104759

8.1HIGH

What is CVE-2026-104759?

The WPO365 | Login plugin for WordPress suffers from an authentication bypass vulnerability due to a flaw in the nonce verification process. The plugin leverages the wp_verify_nonce() function to validate a nonce generated by the Nonce_Service::create_nonce(). However, the nonce produced is a 64-character hex value incompatible with the verification method, leading the check to fail silently. This allows attackers to replay previously issued valid id_token tokens for unauthorized access to any WordPress user account, including those with administrative privileges. It is important to note that this vulnerability is exploitable only when the use_id_token_parser_v2 option is activated, thus routing token processing through a deprecated parser that lacks proper nonce validation.

Affected Version(s)

WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) 0 <= 44.1

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.