Stored Cross-Site Scripting Vulnerability in WPO365 Plugin for WordPress
CVE-2026-96765

7.2HIGH

What is CVE-2026-96765?

The WPO365 | LOGIN plugin for WordPress introduces a vulnerability that allows unauthenticated attackers to exploit the 'id_token' parameter. This exposure is due to inadequate input sanitization and output escaping, enabling attackers to inject malicious scripts into web pages. The injected payloads are stored in wpo365_errors transient data for up to three days. By submitting a specially crafted request, attackers can execute harmful scripts whenever the malicious page is accessed by an administrator, requiring no user interaction beyond that point.

Affected Version(s)

WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) 0 <= 44.1

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sebastian Albrecht (mySebbe)
.