Executive brief
The WPO365 | Login plugin for WordPress, which integrates Microsoft services with WordPress sites, contains a security flaw that allows attackers to change the plugin's settings. By tricking a site administrator into clicking a malicious link, an attacker can gain administrative control over the website or modify user roles. This could lead to a full site takeover and unauthorized access to sensitive data.
Technical details
The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to a failure in the Ajax_Service::verify_ajax_request() helper. The function gates its wp_verify_nonce() call behind an 'enable_nonce_check' option that is absent from the default configuration, causing it to evaluate to false. Consequently, the wp_ajax_wpo365_update_settings handler accepts cross-origin POST requests. An attacker can provide a base64/JSON 'settings' payload that is merged into the plugin's options without an allowlist. This allows an unauthenticated attacker to enable the SCIM REST endpoint, set a known secret token, and change the default user role to 'administrator' by inducing an authenticated administrator to interact with a malicious link.
Affected products
- WPO365 WPO365 | Login up to, and including, 43.2
Timeline
- 2026-07-23: advisory: NVD publication date
- 2026-07-23: disclosed: Wordfence disclosure date