Description
The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Authentication Bypass via OIDC Nonce Replay in all versions up to, and including, 44.1 This is due to `Id_Token_Service_Deprecated::process_openidconnect_token()` using the incompatible WordPress core `wp_verify_nonce()` function to validate a nonce produced by `Nonce_Service::create_nonce()` — a 64-character hex value that `wp_verify_nonce()` can never successfully verify — causing the nonce check to silently fail without terminating authentication, so execution continues into `authenticate_oidc_user()` with the attacker-supplied `id_token`. This makes it possible for unauthenticated attackers who have obtained a previously-issued, valid `id_token` for a target account to replay that token and authenticate as any WordPress user, including administrators, resulting in full site takeover. This vulnerability is only exploitable when the `use_id_token_parser_v2` plugin option is enabled, as this is the configuration that routes token processing through the deprecated parser containing the broken nonce check.
Published: 2026-10-10
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: Authentication Bypass
Action: Patch Immediately
AI Analysis

Impact

The vulnerability in the WPO365 WordPress plugin allows an unauthenticated attacker to bypass authentication by replaying a previously issued id_token. A nonce generated by the plugin is verified incorrectly, causing the nonce check to silently fail and permitting the attacker to authenticate as any WordPress user, including administrators, leading to a complete site takeover. This flaw is classified as CWE-287, an authentication bypass weakness.

Affected Systems

All installations of the WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION plugin up to and including version 44.1 are affected. Upgrading to version 45.0 or later removes the vulnerability.

Risk and Exploitability

With a CVSS score of 8.1, the vulnerability is considered high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, exploiting the OIDC authentication flow; the attacker must obtain a valid id_token for the target account and enable the use_id_token_parser_v2 option, which routes token processing through the vulnerable parser.

Generated by OpenCVE AI on October 10, 2026 at 09:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the WPO365 plugin to version 45.0 or later to apply the official fix.
  • If an upgrade cannot be performed immediately, disable the "use_id_token_parser_v2" plugin option to prevent routing through the vulnerable parser.
  • Verify that the plugin configuration no longer uses the Deprecated Id Token Parser and that ID tokens are processed by the updated service.

Generated by OpenCVE AI on October 10, 2026 at 09:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Description The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Authentication Bypass via OIDC Nonce Replay in all versions up to, and including, 44.1 This is due to `Id_Token_Service_Deprecated::process_openidconnect_token()` using the incompatible WordPress core `wp_verify_nonce()` function to validate a nonce produced by `Nonce_Service::create_nonce()` — a 64-character hex value that `wp_verify_nonce()` can never successfully verify — causing the nonce check to silently fail without terminating authentication, so execution continues into `authenticate_oidc_user()` with the attacker-supplied `id_token`. This makes it possible for unauthenticated attackers who have obtained a previously-issued, valid `id_token` for a target account to replay that token and authenticate as any WordPress user, including administrators, resulting in full site takeover. This vulnerability is only exploitable when the `use_id_token_parser_v2` plugin option is enabled, as this is the configuration that routes token processing through the deprecated parser containing the broken nonce check.
Title WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 44.1 - Unauthenticated Authentication Bypass via OIDC Nonce Replay via id_token Nonce Verification
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T07:41:47.371Z

Reserved: 2026-10-02T12:27:26.024Z

Link: CVE-2026-104759

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T08:17:04.070

Modified: 2026-10-10T08:17:04.070

Link: CVE-2026-104759

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T09:30:04Z

Weaknesses