Impact
The WPO365 "SEAMLESS WORDPRESS + MICROSOFT INTEGRATION" plugin is afflicted with a stored cross‑site scripting flaw. By submitting a crafted id_token claim that contains malicious HTML, an attacker can store arbitrary script code in a transient. When an administrator later visits the wizard page, the embedded scripts execute in the admin context, providing the attacker with the ability to run malicious JavaScript in the victims’ browsers, steal session data, and perform other client‑side attacks.
Affected Systems
Any installation of the WPO365 plugin for WordPress with a version of 44.1 or earlier is vulnerable. This includes all WordPress sites that have not upgraded to the fixed 45.0 release or newer.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.2, indicating a high severity. No EPSS score is available, and the flaw is not currently listed in CISA’s KEV catalog. The flaw can be exploited without authentication by malicious actors, making it readily actionable for attackers who can craft a malicious token and trigger the storage of the payload. The resulting stored XSS can compromise administrator sessions and lead to further exploitation.
OpenCVE Enrichment