Impact
The vulnerability in the WPO365 WordPress plugin allows an unauthenticated attacker to bypass authentication by replaying a previously issued id_token. A nonce generated by the plugin is verified incorrectly, causing the nonce check to silently fail and permitting the attacker to authenticate as any WordPress user, including administrators, leading to a complete site takeover. This flaw is classified as CWE-287, an authentication bypass weakness.
Affected Systems
All installations of the WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION plugin up to and including version 44.1 are affected. Upgrading to version 45.0 or later removes the vulnerability.
Risk and Exploitability
With a CVSS score of 8.1, the vulnerability is considered high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, exploiting the OIDC authentication flow; the attacker must obtain a valid id_token for the target account and enable the use_id_token_parser_v2 option, which routes token processing through the vulnerable parser.
OpenCVE Enrichment