Cross-Site Request Forgery in WPO365 | Login Plugin for WordPress
CVE-2026-15212

8.8HIGH

What is CVE-2026-15212?

The WPO365 | Login plugin for WordPress is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability that affects versions up to and including 43.2. This flaw arises because the Ajax_Service::verify_ajax_request() function does not properly enforce nonce checks, allowing unauthenticated attackers to exploit vulnerable sites. An attacker can manipulate the wp_ajax_wpo365_update_settings handler to submit unauthorized POST requests, resulting in unauthorized changes to plugin options without sufficient validation. This can enable critical settings adjustments, such as empowering the SCIM REST endpoint or altering user roles.

Affected Version(s)

WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) 0 <= 43.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Osvaldo Noe Gonzalez Del Rio (Os)
.