Impact
The All‑In‑One Microsoft 365 & Entra ID / Azure AD SSO Login plugin for WordPress allows an unauthenticated attacker to bypass normal login checks and authenticate as any account, including site administrators. This vulnerability can be exploited simply by sending a crafted request to the plugin’s authentication endpoint, resulting in unauthorized disclosure of administrative privileges and the potential to modify content, install malware, or compromise the entire site. The flaw is consistent with CWE‑288, a failure to verify the authenticity of credentials.
Affected Systems
The vulnerability affects the Cyberlord92 All‑In‑One Microsoft 365 & Entra ID / Azure AD SSO Login plugin for WordPress. All releases through and including version 2.2.5 are impacted, and any site that has not yet updated to a newer version is potentially exposed.
Risk and Exploitability
With a CVSS score of 9.8 the flaw is considered critical, yet its EPSS score indicates a very low probability of exploitation at this time (<1 %). The plugin is not listed in the CISA KEV catalog. The most likely attack vector is over the web; an attacker only needs unauthenticated access to the site’s login interface, making the exploitation straightforward for anyone who can reach the affected WordPress instance.
OpenCVE Enrichment