VYPR

WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION

by WordPress

CVEs (2)

  • CVE-2026-104759HigOct 10, 2026
    risk 0.46cvss 8.1epss —

    The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Authentication Bypass via OIDC Nonce Replay in all versions up to, and including, 44.1 This is due to `Id_Token_Service_Deprecated::process_openidconnect_token()` using…

  • CVE-2026-96765HigOct 10, 2026
    risk 0.40cvss 7.2epss —

    The WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id_token' parameter in all versions up to, and including, 44.1 due to insufficient input sanitization and output escaping. This…