cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forwpo365-login wpo365-login

Direction: ascending
Jun 06, 2024

WordPress + Microsoft Office 365 / Azure AD | LOGIN # CVE-2024-4706

CVE, Research URL

CVE-2024-4706

Date
May 23, 2024
Research Description
The WordPress + Microsoft Office 365 / Azure AD | LOGIN plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pintra' shortcode in all versions up to, and including, 27.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected versions
max 28.0.
Status
vulnerable

WordPress + Microsoft Office 365 / Azure AD | LOGIN # CVE-2021-43409

CVE, Research URL

CVE-2021-43409

Date
Nov 19, 2021
Research Description
The “WPO365 | LOGIN” WordPress plugin (up to and including version 15.3) by wpo365.com is vulnerable to a persistent Cross-Site Scripting (XSS) vulnerability (also known as Stored or Second-Order XSS). Persistent XSS vulnerabilities occur when the application stores and retrieves client supplied data without proper handling of dangerous content. This type of XSS vulnerability is exploited by submitting malicious script content to the application which is then retrieved and executed by other application users. The attacker could exploit this to conduct a range of attacks against users of the affected application such as session hijacking, account take over and accessing sensitive data. In this case, the XSS payload can be submitted by any anonymous user, the payload then renders and executes when a WordPress administrator authenticates and accesses the WordPress Dashboard. The injected payload can carry out actions on behalf of the administrator including adding other administrative users and changing application settings. This flaw could be exploited to ultimately provide full control of the affected system to the attacker.
Affected versions
max 15.4.
Status
vulnerable

WordPress + Microsoft Office 365 / Azure AD | LOGIN # CVE-2020-26511

CVE, Research URL

CVE-2020-26511

Date
Oct 02, 2020
Research Description
The wpo365-login plugin before v11.7 for WordPress allows use of a symmetric algorithm to decrypt a JWT token. This leads to authentication bypass.
Affected versions
max 11.7.
Status
vulnerable
Jan 27, 2026

WordPress + Microsoft Office 365 / Azure AD | LOGIN # CVE-2025-67961

CVE, Research URL

CVE-2025-67961

Date
Jan 22, 2026
Research Description
Server-Side Request Forgery (SSRF) vulnerability in Marco van Wieren WPO365 wpo365-login allows Server Side Request Forgery.This issue affects WPO365: from n/a through <= 40.0.
Affected versions
max 40.1.
Status
vulnerable
Jul 29, 2026

WordPress + Microsoft Office 365 / Azure AD | LOGIN # CVE-2026-15212

CVE, Research URL

CVE-2026-15212

Date
Jul 24, 2026
Research Description
The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. This is due to the Ajax_Service::verify_ajax_request() helper gating its wp_verify_nonce() call behind the boolean option 'enable_nonce_check', which is absent from the default 'wpo365_options' array and therefore evaluates to false via get_global_boolean_var(); as a result, the wp_ajax_wpo365_update_settings handler (Ajax_Service::update_settings) accepts POSTs from cross-origin pages and forwards the attacker-supplied 'settings' payload (base64/JSON) to Options_Service::update_options(), which merges every key/value into wpo365_options without a key allowlist. This makes it possible for unauthenticated attackers to overwrite arbitrary plugin options — including enabling the SCIM REST endpoint (enable_scim), planting an attacker-known scim_secret_token, and setting new_usr_default_role to 'administrator' — via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected versions
max 43.3.
Status
vulnerable
Oct 07, 2026

WordPress + Microsoft Office 365 / Azure AD | LOGIN # CVE-2026-102915

CVE, Research URL

CVE-2026-102915

Date
Oct 06, 2026
Research Description
Subscriber Broken Access Control in WPO365 <= 44.1 versions.
Affected versions
max 44.1.
Status
vulnerable