Description
The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id_token' parameter in all versions up to, and including, 44.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload is stored in the wpo365_errors transient for up to three days by submitting a crafted unauthenticated request with a forged id_token whose base64url-decoded unique_name or iss claim contains malicious HTML, requiring no prior authentication or user interaction beyond an administrator later visiting the WPO365 wizard page.
Published: 2026-10-10
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Stored Cross‑Site Scripting that permits unauthenticated attackers to inject and execute scripts in the WPO365 WordPress admin wizard page, potentially exposing users to script‑based theft or malicious actions
Action: Patch Now
AI Analysis

Impact

The WPO365 "SEAMLESS WORDPRESS + MICROSOFT INTEGRATION" plugin is afflicted with a stored cross‑site scripting flaw. By submitting a crafted id_token claim that contains malicious HTML, an attacker can store arbitrary script code in a transient. When an administrator later visits the wizard page, the embedded scripts execute in the admin context, providing the attacker with the ability to run malicious JavaScript in the victims’ browsers, steal session data, and perform other client‑side attacks.

Affected Systems

Any installation of the WPO365 plugin for WordPress with a version of 44.1 or earlier is vulnerable. This includes all WordPress sites that have not upgraded to the fixed 45.0 release or newer.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.2, indicating a high severity. No EPSS score is available, and the flaw is not currently listed in CISA’s KEV catalog. The flaw can be exploited without authentication by malicious actors, making it readily actionable for attackers who can craft a malicious token and trigger the storage of the payload. The resulting stored XSS can compromise administrator sessions and lead to further exploitation.

Generated by OpenCVE AI on October 10, 2026 at 09:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the WPO365 plugin to version 45.0 or later, which removes the insecure handling of the id_token claim.
  • If the upgrade cannot be performed immediately, disable or uninstall the WPO365 plugin to eliminate the attack surface.
  • Clear the wpo365_errors transient or purge all plugin‑related transients to remove any stored malicious scripts from the database.

Generated by OpenCVE AI on October 10, 2026 at 09:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Description The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id_token' parameter in all versions up to, and including, 44.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The payload is stored in the wpo365_errors transient for up to three days by submitting a crafted unauthenticated request with a forged id_token whose base64url-decoded unique_name or iss claim contains malicious HTML, requiring no prior authentication or user interaction beyond an administrator later visiting the WPO365 wizard page.
Title WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) <= 44.1 - Unauthenticated Stored Cross-Site Scripting via 'id_token' Parameter (iss / unique_name JWT claims)
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-10T07:41:45.478Z

Reserved: 2026-09-23T16:04:46.323Z

Link: CVE-2026-96765

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T08:17:08.170

Modified: 2026-10-10T08:17:08.170

Link: CVE-2026-96765

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T09:45:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')