Stored Cross-Site Scripting Vulnerability in WPO365 Plugin for WordPress
CVE-2026-96765
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 October 2026
What is CVE-2026-96765?
The WPO365 | LOGIN plugin for WordPress introduces a vulnerability that allows unauthenticated attackers to exploit the 'id_token' parameter. This exposure is due to inadequate input sanitization and output escaping, enabling attackers to inject malicious scripts into web pages. The injected payloads are stored in wpo365_errors transient data for up to three days. By submitting a specially crafted request, attackers can execute harmful scripts whenever the malicious page is accessed by an administrator, requiring no user interaction beyond that point.
Affected Version(s)
WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) 0 <= 44.1